Aggiornamenti Mensili Microsoft (AL04/260812/CSIRT-ITA)
Data:
12 Agosto 2026
Impatto Sistemico
Critico (76.66)
Sintesi
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 420 nuove vulnerabilità, di cui 1 di tipo 0-day.
Tipologia
- Elevation of Privilege
- Security Feature Bypass
- Remote Code Execution
- Spoofing
- Information Disclosure
- Tampering
- Denial of Service
Descrizione e potenziali impatti
Nel dettaglio le vulnerabilità sfruttate attivamente o per le quali risulta disponibile in rete un “proof of concept”, riguardano:
- Windows Ancillary Function Driver for WinSock: identificata tramite la CVE-2026-68820, di tipo “Use After Free” e con score CVSS v3.1 pari a 7, presente nel driver Windows Ancillary Function per WinSock. Tale vulnerabilità potrebbe consentire, a un utente autenticato localmente, l’esecuzione di un’applicazione opportunamente predisposta sul sistema interessato al fine di innescare una race condition e ottenere i privilegi di livello SYSTEM.
- Windows Container Isolation FS Filter Driver (unionfs.sys): identificata tramite la CVE-2026-72971, di tipo “Tampering” e con score CVSS v3.1 pari a 5.5, interessa il driver Windows Container Isolation FS Filter (
unionfs.sys). Tale vulnerabilità è dovuta a un’errata risoluzione dei link prima dell’accesso ai file ( link following ), e consentirebbe a un utente autenticato la possibilità di effettuare operazioni non autorizzate a livello locale. - Windows User Profile Service: identificata tramite la CVE-2026-62832, di tipo “Elevation of Privilege” e con score CVSS v3.1 pari a 7.8, interessa la componente Windows User Profile Service. La vulnerabilità è dovuta a un’errata risoluzione dei link prima dell’accesso ai file ( link following ): un utente locale in possesso delle credenziali di un secondo account (anch’esso locale) potrebbe sfruttare tale vulnerabilità eseguendo un’applicazione opportunamente predisposta al fine di caricare l’hive del registro del secondo utente, accedendo e/o modificando i dati di quest’ultimo e ottenendo potenzialmente privilegi amministrativi, senza che sia richiesta alcuna interazione da parte dell’utente interessato.
Prodotti e/o versioni affette
- .NET
- .NET Framework
- AMD Zen
- Active Directory Certificate Services (AD CS)
- Application Information Services
- Application Insights Profiler
- Azure Active Directory
- Azure Confidential Ledger
- Azure CycleCloud
- Azure Entra ID
- Azure Logic Apps
- Azure Monitor Agent
- Azure SQL Database
- Azure SQL Managed Instance
- Azure SRE Agent
- Azure Service Bus
- Azure Storage Explorer
- Capability Access Management Service (camsvc)
- Copilot Cowork
- Desktop Window Manager
- Dynamics Business Central
- GitHub Copilot and Visual Studio Code
- Microsoft 365 Admin Center
- Microsoft Azure Attestation service and Device Health Attestation Service
- Microsoft Azure Kubernetes Service
- Microsoft COM for Windows
- Microsoft Defender for Endpoint
- Microsoft Digest Authentication
- Microsoft Dynamics 365 (on-premises)
- Microsoft Edge (Chromium-based)
- Microsoft Entra Connect Sync
- Microsoft Entra Provisioning Service (SyncFabric)
- Microsoft Exchange Server
- Microsoft High Performance Computing (HPC) Pack
- Microsoft Local Security Authority Server (lsasrv)
- Microsoft Office
- Microsoft Office Access
- Microsoft Office Excel
- Microsoft Office Outlook
- Microsoft Office PowerPoint
- Microsoft Office SharePoint
- Microsoft Office Word
- Microsoft OneDrive
- Microsoft Planetary Computer Pro
- Microsoft PowerShell
- Microsoft PowerShell Core
- Microsoft Purview eDiscovery
- Microsoft QUIC
- Microsoft Remote Registry Service
- Microsoft Teams
- Microsoft Teams Mobile
- Microsoft Teams for Android
- Microsoft Windows Search Component
- Power BI
- RPC Runtime
- Reliable Multicast Transport Driver (RMCAST)
- Remote Desktop Client
- User-Mode Power Service (UMPS)
- Virtual Hard Disk (VHD) Miniport Driver
- Visual Studio Code
- Visual Studio Code – Python extension
- Visual Studio Code CoPilot Chat Extension
- Windows Accessibility Infrastructure (ATBroker.exe)
- Windows Active Directory
- Windows Ancillary Function Driver for WinSock
- Windows Autopilot
- Windows Backup Engine
- Windows Bind Filter Driver
- Windows Cloud Files Mini Filter Driver
- Windows Common Log File System Driver
- Windows Container Isolation FS Filter Driver (unionfs.sys)
- Windows Cross Device Service
- Windows DHCP Client
- Windows DHCP Server
- Windows DNS
- Windows DWM Core Library
- Windows Defender Firewall Service
- Windows Deployment Services
- Windows Device Association Service
- Windows Display Enhancement Service
- Windows Encrypting File System (EFS)
- Windows Event Logging Service
- Windows GDI
- Windows GDI+
- Windows Graphics Kernel
- Windows HTTP Protocol Stack
- Windows HTTP.sys
- Windows Hello
- Windows Hyper-V
- Windows Imaging Component
- Windows Installer
- Windows Kerberos
- Windows Kernel
- Windows Key Guard
- Windows LDAP – Lightweight Directory Access Protocol
- Windows LUAFV
- Windows License Manager
- Windows MIDI Service Module
- Windows Management Instrumentation
- Windows Management Services
- Windows Message Queuing
- Windows Modern Device Management (MDM)
- Windows NTFS
- Windows Narrator Braille
- Windows Network Address Translation (NAT)
- Windows Network Connection Broker
- Windows Network File System
- Windows Package Manager
- Windows Program Compatibility Assistant Service
- Windows Projected File System
- Windows Push Notifications
- Windows RPC API
- Windows Remote Access API
- Windows Remote Access Connection Manager
- Windows Remote Desktop Services
- Windows Routing and Remote Access Service (RRAS)
- Windows SMB Client
- Windows SMB Server
- Windows Schannel
- Windows Secure Socket Tunneling Protocol (SSTP)
- Windows Sensor Data Service
- Windows Shell
- Windows Storage
- Windows Storage Port Driver
- Windows TCP/IP
- Windows Telephony Service
- Windows USB Driver
- Windows Universal Disk Format File System Driver (UDFS)
- Windows User Profile Service
- Windows Win32K
- Windows Wired AutoConfig Service
- Windows Work Folder Service
- Windows iSCSI Target Service
- Winlogon
Azioni di mitigazione
In linea con le dichiarazioni del vendor, si raccomanda di procedere all’aggiornamento dei prodotti impattati attraverso l’apposita funzione di Windows Update.
Riferimenti
- https://msrc.microsoft.com/update-guide
- https://msrc.microsoft.com/update-guide/releaseNote/2026-aug
CVE
Change log
| Versione | Note | Data |
|---|---|---|
| 1.0 | Pubblicato il 12-08-2026 | 12/08/2026 |
Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità. Può essere visualizzato in versione originale al seguente link
Ultimo aggiornamento
12 Agosto 2026, 10:20
CSIRT Toscana