Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584

Scheduled Pinned Locked Moved Uncategorized
12 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

    Security Update Guide - Microsoft Security Response Center

    favicon

    (msrc.microsoft.com)

    One job. You had one job.

    Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

    lucaswerkmeister@wikis.worldL This user is from outside of this forum
    lucaswerkmeister@wikis.worldL This user is from outside of this forum
    lucaswerkmeister@wikis.world
    wrote last edited by
    #3

    @nyanbinary Microsoft Offender

    nyanbinary@infosec.exchangeN 1 Reply Last reply
    0
    • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

      Security Update Guide - Microsoft Security Response Center

      favicon

      (msrc.microsoft.com)

      One job. You had one job.

      Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

      nyanbinary@infosec.exchangeN This user is from outside of this forum
      nyanbinary@infosec.exchangeN This user is from outside of this forum
      nyanbinary@infosec.exchange
      wrote last edited by
      #4

      Successful exploitation of this vulnerability would require a remote, unauthenticated attacker to entice a local user to take multiple actions that results in Defender scanning a malicious file that has been quarantined.

      This is something I love about some AV vulnerabilities - intentionally triggering detections as part of exploitation. Also had that with the Nightmare Eclipse Defender vulns & also had me giggle there . I just ... feels right!

      1 Reply Last reply
      0
      • lucaswerkmeister@wikis.worldL lucaswerkmeister@wikis.world

        @nyanbinary Microsoft Offender

        nyanbinary@infosec.exchangeN This user is from outside of this forum
        nyanbinary@infosec.exchangeN This user is from outside of this forum
        nyanbinary@infosec.exchange
        wrote last edited by
        #5

        @LucasWerkmeister the best defense is a good offense. This is why the A in AV now stands for Agentic, performing fully autonomous cyber offense operations from your laptop!

        1 Reply Last reply
        0
        • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

          Security Update Guide - Microsoft Security Response Center

          favicon

          (msrc.microsoft.com)

          One job. You had one job.

          Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

          bws@social.linux.pizzaB This user is from outside of this forum
          bws@social.linux.pizzaB This user is from outside of this forum
          bws@social.linux.pizza
          wrote last edited by
          #6

          @nyanbinary maybe the 11 in windows 11 meant the cvss score?

          1 Reply Last reply
          0
          • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

            Security Update Guide - Microsoft Security Response Center

            favicon

            (msrc.microsoft.com)

            One job. You had one job.

            Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

            catsalad@infosec.exchangeC This user is from outside of this forum
            catsalad@infosec.exchangeC This user is from outside of this forum
            catsalad@infosec.exchange
            wrote last edited by
            #7

            @nyanbinary I'm sure they learned their lesson and won't let it ever happen again!

            rk@mastodon.well.comR abt1181@ioc.exchangeA 2 Replies Last reply
            0
            • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

              Security Update Guide - Microsoft Security Response Center

              favicon

              (msrc.microsoft.com)

              One job. You had one job.

              Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

              malwareminigun@infosec.exchangeM This user is from outside of this forum
              malwareminigun@infosec.exchangeM This user is from outside of this forum
              malwareminigun@infosec.exchange
              wrote last edited by
              #8

              @nyanbinary

              Link Preview Image
              1 Reply Last reply
              0
              • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

                Security Update Guide - Microsoft Security Response Center

                favicon

                (msrc.microsoft.com)

                One job. You had one job.

                Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote last edited by
                #9

                @nyanbinary

                1 Reply Last reply
                0
                • catsalad@infosec.exchangeC catsalad@infosec.exchange

                  @nyanbinary I'm sure they learned their lesson and won't let it ever happen again!

                  rk@mastodon.well.comR This user is from outside of this forum
                  rk@mastodon.well.comR This user is from outside of this forum
                  rk@mastodon.well.com
                  wrote last edited by
                  #10

                  @catsalad @nyanbinary

                  Was it Defender that would execute JS without a sandbox and was trivially exploitable like…a few years ago? I think that was them.

                  1 Reply Last reply
                  0
                  • catsalad@infosec.exchangeC catsalad@infosec.exchange

                    @nyanbinary I'm sure they learned their lesson and won't let it ever happen again!

                    abt1181@ioc.exchangeA This user is from outside of this forum
                    abt1181@ioc.exchangeA This user is from outside of this forum
                    abt1181@ioc.exchange
                    wrote last edited by
                    #11

                    @catsalad I stripped Defender out of my Windows 10 LTSC installs and just use my estranged parents' Kaspersky family license lol

                    1 Reply Last reply
                    1
                    0
                    • R relay@relay.infosec.exchange shared this topic
                      R relay@relay.publicsquare.global shared this topic
                    • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

                      Security Update Guide - Microsoft Security Response Center

                      favicon

                      (msrc.microsoft.com)

                      One job. You had one job.

                      Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

                      swym@chaos.socialS This user is from outside of this forum
                      swym@chaos.socialS This user is from outside of this forum
                      swym@chaos.social
                      wrote last edited by
                      #12

                      @nyanbinary they should fire more engineers, so they have more funds for copilot tokens

                      1 Reply Last reply
                      0
                      • R relay@relay.an.exchange shared this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups