FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

CVE-2025-64669: Uncovering Local Privilege Escalation Vulnerability in Windows Admin Center

By: /u/Fun_Preference1113 β€” December 15th 2025 at 17:13

Microsoft has released a fix for CVE-2025-64669, addressing a local privilege escalation vulnerability we reported in Windows Admin Center.
This issue allowed low privileged users to escalate to SYSTEM by abusing trusted components under insecure filesystem permissions. Microsoft validated the finding and shipped a fix as part of the latest update.
This CVE represents only the first vulnerability from our research.
We identified four distinct vulnerabilities during the investigation, and additional fixes and disclosures are coming.
More details soon.
Stay tuned.

submitted by /u/Fun_Preference1113
[link] [comments]
☐ β˜† βœ‡ /r/netsec - Information Security News & Discussion

Entra Id security bypass

By: /u/Fun_Preference1113 β€” August 15th 2024 at 12:00

Check out the new research from my colleague and me - we’ve discovered a security bypass in Azure Entra ID Our findings reveal a vulnerability in pass-through authentication that could potentially allow unauthorized access across synced on-prem domains.

submitted by /u/Fun_Preference1113
[link] [comments]
❌