CSIRT Toscana

Aggiornamenti Mensili Microsoft (AL04/260812/CSIRT-ITA)

Data:
28 Settembre 2026

Impatto Sistemico

Critico (77.05)

Sintesi

Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 420 nuove vulnerabilità, di cui 1 di tipo 0-day.

Tipologia

  • Elevation of Privilege
  • Security Feature Bypass
  • Remote Code Execution
  • Spoofing
  • Information Disclosure
  • Tampering
  • Denial of Service

Descrizione e potenziali impatti

Nel dettaglio le vulnerabilità sfruttate attivamente o per le quali risulta disponibile in rete un “proof of concept”, riguardano:

  • Windows Ancillary Function Driver for WinSock: identificata tramite la CVE-2026-68820, di tipo “Use After Free” e con score CVSS v3.1 pari a 7, presente nel driver Windows Ancillary Function per WinSock. Tale vulnerabilità potrebbe consentire, a un utente autenticato localmente, l’esecuzione di un’applicazione opportunamente predisposta sul sistema interessato al fine di innescare una race condition e ottenere i privilegi di livello SYSTEM.
  • Windows Container Isolation FS Filter Driver (unionfs.sys): identificata tramite la CVE-2026-72971, di tipo “Tampering” e con score CVSS v3.1 pari a 5.5, interessa il driver Windows Container Isolation FS Filter ( unionfs.sys ). Tale vulnerabilità è dovuta a un’errata risoluzione dei link prima dell’accesso ai file ( link following ), e consentirebbe a un utente autenticato la possibilità di effettuare operazioni non autorizzate a livello locale.
  • Windows User Profile Service: identificata tramite la CVE-2026-62832, di tipo “Elevation of Privilege” e con score CVSS v3.1 pari a 7.8, interessa la componente Windows User Profile Service. La vulnerabilità è dovuta a un’errata risoluzione dei link prima dell’accesso ai file ( link following ): un utente locale in possesso delle credenziali di un secondo account (anch’esso locale) potrebbe sfruttare tale vulnerabilità eseguendo un’applicazione opportunamente predisposta al fine di caricare l’hive del registro del secondo utente, accedendo e/o modificando i dati di quest’ultimo e ottenendo potenzialmente privilegi amministrativi, senza che sia richiesta alcuna interazione da parte dell’utente interessato.
  • Windows Kernel : identificata tramite la CVE-2026-62737, di tipo “Untrusted Pointer Dereference” e con score CVSS v3.1 pari a 7.8, interessa il Windows Kernel. La vulnerabilità è dovuta alla gestione non sicura di puntatori controllabili da un utente all’interno di componenti kernel accessibili localmente. Un utente autenticato potrebbe sfruttare tale vulnerabilità al fine di innescare una chiamata indiretta controllata in modalità kernel e ottenere così l’elevazione dei privilegi fino al livello SYSTEM.
  • SharePoint Server : identificata tramite la CVE-2026-63520, di tipo “Improper Input Validation” e con score CVSS v3.1 pari a 8.1, interessa Microsoft SharePoint Server. La vulnerabilità, presente nel sottosistema Business Data Connectivity (BDC), è dovuta alla mancata applicazione delle opportune restrizioni nel processo di istanziazione dei tipi .Net e delle relative proprietà nella classe DbTypeReflector. Un utente autenticato potrebbe sfruttare tale vulnerabilità caricando un modello BDC malevolo, innescando l’esecuzione di una catena di oggetti opportunamente predisposta, al fine di ottenere l’esecuzione di codice arbitrario sul sistema con i privilegi dell’account di servizio del sito.
  • Microsoft Exchange Server: identificata tramite la CVE-2026-62911, di tipo ” Elevation of Privilege” e con score CVSS v3.1 pari a 8.0, interessa Microsoft Exchange Server. La vulnerabilità, per la quale risulta disponibile pubblicamente un proof of concept, consente a un utente malintenzionato remoto autenticato di ottenere un’elevazione dei privilegi, con potenziale impatto sulla confidenzialità, integrità e disponibilità delle informazioni sui sistemi interessati.

Prodotti e/o versioni affette

  • .NET
  • .NET Framework
  • AMD Zen
  • Active Directory Certificate Services (AD CS)
  • Application Information Services
  • Application Insights Profiler
  • Azure Active Directory
  • Azure Confidential Ledger
  • Azure CycleCloud
  • Azure Entra ID
  • Azure Logic Apps
  • Azure Monitor Agent
  • Azure SQL Database
  • Azure SQL Managed Instance
  • Azure SRE Agent
  • Azure Service Bus
  • Azure Storage Explorer
  • Capability Access Management Service (camsvc)
  • Copilot Cowork
  • Desktop Window Manager
  • Dynamics Business Central
  • GitHub Copilot and Visual Studio Code
  • Microsoft 365 Admin Center
  • Microsoft Azure Attestation service and Device Health Attestation Service
  • Microsoft Azure Kubernetes Service
  • Microsoft COM for Windows
  • Microsoft Defender for Endpoint
  • Microsoft Digest Authentication
  • Microsoft Dynamics 365 (on-premises)
  • Microsoft Edge (Chromium-based)
  • Microsoft Entra Connect Sync
  • Microsoft Entra Provisioning Service (SyncFabric)
  • Microsoft Exchange Server
  • Microsoft High Performance Computing (HPC) Pack
  • Microsoft Local Security Authority Server (lsasrv)
  • Microsoft Office
  • Microsoft Office Access
  • Microsoft Office Excel
  • Microsoft Office Outlook
  • Microsoft Office PowerPoint
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft OneDrive
  • Microsoft Planetary Computer Pro
  • Microsoft PowerShell
  • Microsoft PowerShell Core
  • Microsoft Purview eDiscovery
  • Microsoft QUIC
  • Microsoft Remote Registry Service
  • Microsoft Teams
  • Microsoft Teams Mobile
  • Microsoft Teams for Android
  • Microsoft Windows Search Component
  • Power BI
  • RPC Runtime
  • Reliable Multicast Transport Driver (RMCAST)
  • Remote Desktop Client
  • User-Mode Power Service (UMPS)
  • Virtual Hard Disk (VHD) Miniport Driver
  • Visual Studio Code
  • Visual Studio Code – Python extension
  • Visual Studio Code CoPilot Chat Extension
  • Windows Accessibility Infrastructure (ATBroker.exe)
  • Windows Active Directory
  • Windows Ancillary Function Driver for WinSock
  • Windows Autopilot
  • Windows Backup Engine
  • Windows Bind Filter Driver
  • Windows Cloud Files Mini Filter Driver
  • Windows Common Log File System Driver
  • Windows Container Isolation FS Filter Driver (unionfs.sys)
  • Windows Cross Device Service
  • Windows DHCP Client
  • Windows DHCP Server
  • Windows DNS
  • Windows DWM Core Library
  • Windows Defender Firewall Service
  • Windows Deployment Services
  • Windows Device Association Service
  • Windows Display Enhancement Service
  • Windows Encrypting File System (EFS)
  • Windows Event Logging Service
  • Windows GDI
  • Windows GDI+
  • Windows Graphics Kernel
  • Windows HTTP Protocol Stack
  • Windows HTTP.sys
  • Windows Hello
  • Windows Hyper-V
  • Windows Imaging Component
  • Windows Installer
  • Windows Kerberos
  • Windows Kernel
  • Windows Key Guard
  • Windows LDAP – Lightweight Directory Access Protocol
  • Windows LUAFV
  • Windows License Manager
  • Windows MIDI Service Module
  • Windows Management Instrumentation
  • Windows Management Services
  • Windows Message Queuing
  • Windows Modern Device Management (MDM)
  • Windows NTFS
  • Windows Narrator Braille
  • Windows Network Address Translation (NAT)
  • Windows Network Connection Broker
  • Windows Network File System
  • Windows Package Manager
  • Windows Program Compatibility Assistant Service
  • Windows Projected File System
  • Windows Push Notifications
  • Windows RPC API
  • Windows Remote Access API
  • Windows Remote Access Connection Manager
  • Windows Remote Desktop Services
  • Windows Routing and Remote Access Service (RRAS)
  • Windows SMB Client
  • Windows SMB Server
  • Windows Schannel
  • Windows Secure Socket Tunneling Protocol (SSTP)
  • Windows Sensor Data Service
  • Windows Shell
  • Windows Storage
  • Windows Storage Port Driver
  • Windows TCP/IP
  • Windows Telephony Service
  • Windows USB Driver
  • Windows Universal Disk Format File System Driver (UDFS)
  • Windows User Profile Service
  • Windows Win32K
  • Windows Wired AutoConfig Service
  • Windows Work Folder Service
  • Windows iSCSI Target Service
  • Winlogon

Azioni di mitigazione

In linea con le dichiarazioni del vendor, si raccomanda di procedere all’aggiornamento dei prodotti impattati attraverso l’apposita funzione di Windows Update.

Riferimenti

CVE

CVE-ID
CVE-2026-65660 CVE-2026-68820 CVE-2026-72971 CVE-2026-63520
CVE-2026-62911 CVE-2026-62832 CVE-2026-62737 CVE-2026-71331
CVE-2026-70355 CVE-2026-70354 CVE-2026-70348 CVE-2026-70347
CVE-2026-70346 CVE-2026-70345 CVE-2026-70344 CVE-2026-70340
CVE-2026-70339 CVE-2026-70338 CVE-2026-70337 CVE-2026-70336
CVE-2026-70335 CVE-2026-70332 CVE-2026-70330 CVE-2026-70329
CVE-2026-70328 CVE-2026-70327 CVE-2026-70326 CVE-2026-70325
CVE-2026-70324 CVE-2026-70323 CVE-2026-70322 CVE-2026-70321
CVE-2026-70320 CVE-2026-70319 CVE-2026-70318 CVE-2026-70317
CVE-2026-70316 CVE-2026-70315 CVE-2026-70314 CVE-2026-70313
CVE-2026-70312 CVE-2026-70311 CVE-2026-70310 CVE-2026-70307
CVE-2026-70306 CVE-2026-70304 CVE-2026-70130 CVE-2026-69320
CVE-2026-69306 CVE-2026-69278 CVE-2026-68823 CVE-2026-68821
CVE-2026-68819 CVE-2026-68817 CVE-2026-68816 CVE-2026-68815
CVE-2026-68814 CVE-2026-68813 CVE-2026-68812 CVE-2026-68811
CVE-2026-68810 CVE-2026-68809 CVE-2026-68808 CVE-2026-68807
CVE-2026-68806 CVE-2026-68805 CVE-2026-68804 CVE-2026-68803
CVE-2026-68802 CVE-2026-68801 CVE-2026-68800 CVE-2026-68799
CVE-2026-68798 CVE-2026-68797 CVE-2026-68796 CVE-2026-68795
CVE-2026-68794 CVE-2026-68793 CVE-2026-68792 CVE-2026-66810
CVE-2026-66809 CVE-2026-66808 CVE-2026-66807 CVE-2026-66806
CVE-2026-66805 CVE-2026-66804 CVE-2026-66802 CVE-2026-66799
CVE-2026-66301 CVE-2026-65815 CVE-2026-65814 CVE-2026-65813
CVE-2026-65811 CVE-2026-65810 CVE-2026-65807 CVE-2026-65806
CVE-2026-65799 CVE-2026-65798 CVE-2026-65797 CVE-2026-65796
CVE-2026-65795 CVE-2026-65794 CVE-2026-65791 CVE-2026-65790
CVE-2026-65789 CVE-2026-65788 CVE-2026-65787 CVE-2026-65786
CVE-2026-65785 CVE-2026-65784 CVE-2026-65783 CVE-2026-65782
CVE-2026-65781 CVE-2026-65780 CVE-2026-65779 CVE-2026-65778
CVE-2026-65777 CVE-2026-65776 CVE-2026-65775 CVE-2026-65774
CVE-2026-65773 CVE-2026-65769 CVE-2026-65768 CVE-2026-65767
CVE-2026-65681 CVE-2026-65680 CVE-2026-65679 CVE-2026-65678
CVE-2026-65675 CVE-2026-65673 CVE-2026-65672 CVE-2026-65671
CVE-2026-65668 CVE-2026-65667 CVE-2026-65665 CVE-2026-65664
CVE-2026-65663 CVE-2026-65662 CVE-2026-65661 CVE-2026-65658
CVE-2026-65657 CVE-2026-65656 CVE-2026-64922 CVE-2026-64921
CVE-2026-64920 CVE-2026-64919 CVE-2026-64917 CVE-2026-64916
CVE-2026-64915 CVE-2026-64914 CVE-2026-64912 CVE-2026-64911
CVE-2026-64910 CVE-2026-64909 CVE-2026-64908 CVE-2026-64907
CVE-2026-64906 CVE-2026-64905 CVE-2026-64904 CVE-2026-64903
CVE-2026-64902 CVE-2026-64901 CVE-2026-64900 CVE-2026-64899
CVE-2026-64898 CVE-2026-64897 CVE-2026-63533 CVE-2026-63532
CVE-2026-63531 CVE-2026-63530 CVE-2026-63529 CVE-2026-63528
CVE-2026-63527 CVE-2026-63526 CVE-2026-63525 CVE-2026-63524
CVE-2026-63522 CVE-2026-63521 CVE-2026-63519 CVE-2026-63518
CVE-2026-63517 CVE-2026-63516 CVE-2026-63515 CVE-2026-63514
CVE-2026-63513 CVE-2026-63512 CVE-2026-63508 CVE-2026-62918
CVE-2026-62917 CVE-2026-62915 CVE-2026-62914 CVE-2026-62913
CVE-2026-62912 CVE-2026-62910 CVE-2026-62909 CVE-2026-62908
CVE-2026-62902 CVE-2026-62901 CVE-2026-62900 CVE-2026-62899
CVE-2026-62898 CVE-2026-62897 CVE-2026-62896 CVE-2026-62894
CVE-2026-62893 CVE-2026-62892 CVE-2026-62890 CVE-2026-62889
CVE-2026-62888 CVE-2026-62887 CVE-2026-62886 CVE-2026-62885
CVE-2026-62883 CVE-2026-62882 CVE-2026-62881 CVE-2026-62880
CVE-2026-62878 CVE-2026-62877 CVE-2026-62876 CVE-2026-62873
CVE-2026-62872 CVE-2026-62871 CVE-2026-62869 CVE-2026-62842
CVE-2026-62839 CVE-2026-62837 CVE-2026-62836 CVE-2026-62830
CVE-2026-62829 CVE-2026-62827 CVE-2026-62824 CVE-2026-62823
CVE-2026-62822 CVE-2026-62820 CVE-2026-62819 CVE-2026-62818
CVE-2026-62817 CVE-2026-62816 CVE-2026-62815 CVE-2026-62814
CVE-2026-62812 CVE-2026-62811 CVE-2026-62807 CVE-2026-62803
CVE-2026-62800 CVE-2026-62799 CVE-2026-62798 CVE-2026-62797
CVE-2026-62796 CVE-2026-62795 CVE-2026-62793 CVE-2026-62792
CVE-2026-62790 CVE-2026-62788 CVE-2026-62787 CVE-2026-62786
CVE-2026-62785 CVE-2026-62784 CVE-2026-62783 CVE-2026-62782
CVE-2026-62781 CVE-2026-62780 CVE-2026-62779 CVE-2026-62778
CVE-2026-62777 CVE-2026-62776 CVE-2026-62775 CVE-2026-62774
CVE-2026-62773 CVE-2026-62772 CVE-2026-62771 CVE-2026-62770
CVE-2026-62769 CVE-2026-62768 CVE-2026-62766 CVE-2026-62761
CVE-2026-62758 CVE-2026-62757 CVE-2026-62755 CVE-2026-62754
CVE-2026-62753 CVE-2026-62752 CVE-2026-62751 CVE-2026-62750
CVE-2026-62749 CVE-2026-62748 CVE-2026-62747 CVE-2026-62746
CVE-2026-62745 CVE-2026-62743 CVE-2026-62742 CVE-2026-62741
CVE-2026-62740 CVE-2026-62739 CVE-2026-62738 CVE-2026-62736
CVE-2026-62735 CVE-2026-62734 CVE-2026-62733 CVE-2026-62732
CVE-2026-62730 CVE-2026-62729 CVE-2026-62728 CVE-2026-62726
CVE-2026-62725 CVE-2026-62724 CVE-2026-62723 CVE-2026-62722
CVE-2026-62721 CVE-2026-62720 CVE-2026-62719 CVE-2026-62718
CVE-2026-62717 CVE-2026-62716 CVE-2026-62715 CVE-2026-62714
CVE-2026-62713 CVE-2026-62712 CVE-2026-62711 CVE-2026-62710
CVE-2026-62709 CVE-2026-62708 CVE-2026-62707 CVE-2026-62705
CVE-2026-62703 CVE-2026-62702 CVE-2026-62701 CVE-2026-62700
CVE-2026-62699 CVE-2026-62698 CVE-2026-62696 CVE-2026-62695
CVE-2026-62693 CVE-2026-62692 CVE-2026-62690 CVE-2026-62688
CVE-2026-61939 CVE-2026-61938 CVE-2026-61937 CVE-2026-61936
CVE-2026-61934 CVE-2026-61933 CVE-2026-61932 CVE-2026-61930
CVE-2026-61929 CVE-2026-61928 CVE-2026-61927 CVE-2026-61926
CVE-2026-61925 CVE-2026-61924 CVE-2026-61923 CVE-2026-61921
CVE-2026-61920 CVE-2026-61918 CVE-2026-61368 CVE-2026-61367
CVE-2026-61366 CVE-2026-61365 CVE-2026-61364 CVE-2026-61363
CVE-2026-61361 CVE-2026-61360 CVE-2026-61359 CVE-2026-61358
CVE-2026-61357 CVE-2026-61356 CVE-2026-61355 CVE-2026-61353
CVE-2026-61352 CVE-2026-61350 CVE-2026-61349 CVE-2026-61348
CVE-2026-61347 CVE-2026-61346 CVE-2026-61345 CVE-2026-59138
CVE-2026-59137 CVE-2026-59136 CVE-2026-59135 CVE-2026-59134
CVE-2026-59133 CVE-2026-59132 CVE-2026-59131 CVE-2026-59130
CVE-2026-59128 CVE-2026-59127 CVE-2026-59126 CVE-2026-59125
CVE-2026-59124 CVE-2026-59122 CVE-2026-59119 CVE-2026-59118
CVE-2026-59115 CVE-2026-59113 CVE-2026-58651 CVE-2026-58650
CVE-2026-58641 CVE-2026-58639 CVE-2026-58612 CVE-2026-57105
CVE-2026-57104 CVE-2026-56179 CVE-2026-56174 CVE-2026-56162
CVE-2026-56161 CVE-2026-54984 CVE-2026-54981 CVE-2026-54123
CVE-2026-54113 CVE-2026-50516 CVE-2026-50515 CVE-2026-50481
CVE-2026-50472 CVE-2026-49179 CVE-2026-49163 CVE-2026-47299
CVE-2026-47285 CVE-2026-42976 CVE-2026-40375 CVE-2024-26464

Change log

Versione Note Data
1.0 Pubblicato il 12-08-2026 12/08/2026
1.1 Aggiornata la sezione “CVE” con presenza PoC per la CVE-2026-62737. 13/08/2026
1.2 Aggiornata la sezione “CVE” con presenza PoC per la CVE-2026-62911. 11/09/2026
1.3 Aggiornata la sezione “CVE” con presenza PoC per la CVE-2026-65660. 22/09/2026
1.4 Aggiornata la sezione “CVE” per rilevato sfruttamento in rete della CVE-2026-65660. 28/09/2026

Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità. Può essere visualizzato in versione originale al seguente link

Ultimo aggiornamento

28 Settembre 2026, 09:31