CSIRT Toscana

Aggiornamenti Mensili Microsoft (AL01/260610/CSIRT-ITA)

Data:
10 Giugno 2026

Sintesi

Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 206 nuove vulnerabilità.

Tipologia

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Feature Bypass
  • Spoofing
  • Tampering

Descrizione e potenziali impatti

Nel dettaglio le vulnerabilità sfruttate attivamente e/o per alcune delle quali risulta disponibile in rete anche un “proof of concept”, riguardano:

  • Windows Collaborative Translation Framework: identificata tramite la CVE-2026-45586, di tipo “Elevation of Privilege” e con score CVSS v3.1 pari a 7.8. Tale vulnerabilità interessa il framework di traduzione collaborativa di Windows (componente ctfmon.exe ) ed è causata da una non corretta risoluzione dei collegamenti prima dell’accesso ai file (meccanismo denominato “link following”). Nel dettaglio, un attaccante locale autenticato potrebbe sfruttare questa incongruenza per manipolare il file system ed elevare i propri privilegi fino al livello SYSTEM sul sistema target.
  • HTTP.sys: identificata tramite la CVE-2026-49160, di tipo “Denial of Service” e con score CVSS v3.1 pari a 7.5. Tale vulnerabilità interessa il driver del protocollo HTTP del kernel di Windows (HTTP.sys) ed è dovuta a una gestione non corretta dell’utilizzo delle risorse durante l’elaborazione delle sessioni HTTP/2 (riconducibile a vettori di tipo ” HTTP/2 Bomb “). Nel dettaglio, un attaccante remoto non autenticato potrebbe inviare richieste di rete opportunamente predisposte al fine di esaurire la memoria del server target, provocando il blocco del servizio e la conseguente interruzione della disponibilità dello stesso.
  • Windows BitLocker: identificata tramite la CVE-2026-50507, di tipo “Security Feature Bypass” e con score CVSS v3.1 pari a 6.8. Tale vulnerabilità interessa la funzionalità di cifratura del disco Windows BitLocker e deriva da un’anomalia presente nel meccanismo di protezione ( Protection Mechanism Failure ), dovuta all’assenza di autenticazione durante specifiche fasi di ripristino o avvio. Nel dettaglio, un attaccante con accesso fisico al dispositivo target potrebbe sfruttare tale condiszione per aggirare le restrizioni di sicurezza di BitLocker al fine di ottenere l’accesso diretto ai dati cifrati presenti sull’unità di memoria target.

Prodotti e/o versioni affette

  • .NET
  • ASP.NET Core
  • Active Directory Domain Services
  • Azure HorizonDB
  • Azure Stack Edge
  • Copilot Chat (Microsoft Edge)
  • Function Discovery Service (fdwsd.dll)
  • GitHub Copilot and Visual Studio Code
  • HTTP/2
  • Linux MANA Driver
  • M365 Copilot
  • Microsoft Azure Attestation service and Device Health Attestation Service
  • Microsoft Azure Kubernetes Service
  • Microsoft Bing
  • Microsoft Copilot
  • Microsoft Defender for Endpoint
  • Microsoft Dynamics 365 (on-premises)
  • Microsoft Exchange Online
  • Microsoft Exchange Server
  • Microsoft Graph
  • Microsoft Graphics Component
  • Microsoft Kinect
  • Microsoft Live Share Canvas SDK
  • Microsoft Office
  • Microsoft Office Click-To-Run
  • Microsoft Office Excel
  • Microsoft Office Project
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft PC Manager
  • Microsoft PowerToys
  • Microsoft Teams for Android
  • Microsoft UxTheme Library (uxtheme.dll)
  • Microsoft Windows DNS
  • Nuance PowerScribe
  • Office for Android
  • Remote Desktop Client
  • Role: Windows Hyper-V
  • UI Automation Manager (uiamanager.dll)
  • Universal Plug and Play (upnp.dll)
  • Visual Studio Code
  • Windows Administrator Protection
  • Windows Ancillary Function Driver for WinSock
  • Windows Application Identity (AppID) Subsystem
  • Windows BitLocker
  • Windows Bluetooth Port Driver
  • Windows Bluetooth Service
  • Windows Boot Manager
  • Windows Collaborative Translation Framework
  • Windows Common Log File System Driver
  • Windows Cryptographic Services
  • Windows DHCP Client
  • Windows DHCP Server
  • Windows DWM Core Library
  • Windows Deployment Services
  • Windows HTTP.sys
  • Windows Hotpatch Monitoring Service
  • Windows Hyper-V
  • Windows Internet (wininet.dll)
  • Windows Kerberos
  • Windows Kernel
  • Windows Kernel-Mode Drivers
  • Windows Mark of the Web (MOTW)
  • Windows Media
  • Windows NT OS Kernel
  • Windows NTFS
  • Windows NTLM
  • Windows Narrator Braille
  • Windows Network Controller (NC) Host Agent
  • Windows Performance Monitor
  • Windows Program Compatibility Assistant Service
  • Windows Projected File System Filter Driver
  • Windows Push Notifications
  • Windows RDP
  • Windows SDK
  • Windows Secure Boot
  • Windows Shell
  • Windows Storage
  • Windows TCP/IP
  • Windows Telephony Service
  • Windows UEFI
  • Windows Universal Disk Format File System Driver (UDFS)
  • Windows Win32K – GRFX
  • Winlogon

Azioni di mitigazione

In linea con le dichiarazioni del vendor, si raccomanda di procedere all’aggiornamento dei prodotti impattati attraverso l’apposita funzione di Windows Update.

Riferimenti

CVE

CVE-ID
CVE-2026-45586 CVE-2026-49160 CVE-2026-50507 CVE-2026-41092
CVE-2026-42977 CVE-2026-42974 CVE-2026-42979 CVE-2026-42978
CVE-2026-26142 CVE-2026-42973 CVE-2026-42972 CVE-2026-42971
CVE-2026-42970 CVE-2026-45460 CVE-2026-45461 CVE-2026-47640
CVE-2026-45583 CVE-2026-45462 CVE-2026-44808 CVE-2026-44809
CVE-2026-33113 CVE-2026-44804 CVE-2026-44805 CVE-2026-42987
CVE-2026-42986 CVE-2026-44807 CVE-2026-42985 CVE-2026-47639
CVE-2026-47638 CVE-2026-44801 CVE-2026-44802 CVE-2026-42989
CVE-2026-44803 CVE-2026-45456 CVE-2026-41098 CVE-2026-47635
CVE-2026-42980 CVE-2026-45457 CVE-2026-47634 CVE-2026-45458
CVE-2026-47637 CVE-2026-47636 CVE-2026-45459 CVE-2026-47631
CVE-2026-42984 CVE-2026-45453 CVE-2026-42983 CVE-2026-45454
CVE-2026-45455 CVE-2026-42981 CVE-2026-45591 CVE-2026-45471
CVE-2026-45592 CVE-2026-45472 CVE-2026-45593 CVE-2026-45594
CVE-2026-34335 CVE-2026-44819 CVE-2026-44815 CVE-2026-44817
CVE-2026-44818 CVE-2026-44811 CVE-2026-44812 CVE-2026-44813
CVE-2026-44814 CVE-2026-45467 CVE-2026-45588 CVE-2026-42991
CVE-2026-45468 CVE-2026-45469 CVE-2026-47648 CVE-2026-44810
CVE-2026-45463 CVE-2026-47641 CVE-2026-45464 CVE-2026-47644
CVE-2026-45465 CVE-2026-42993 CVE-2026-45466 CVE-2026-47643
CVE-2026-42992 CVE-2026-45481 CVE-2026-45482 CVE-2026-45483
CVE-2026-45484 CVE-2026-49161 CVE-2026-44822 CVE-2026-44823
CVE-2026-44824 CVE-2026-45599 CVE-2026-45479 CVE-2026-47656
CVE-2026-44820 CVE-2026-44821 CVE-2026-45474 CVE-2026-47653
CVE-2026-45595 CVE-2026-45475 CVE-2026-47652 CVE-2026-45596
CVE-2026-47655 CVE-2026-45476 CVE-2026-45597 CVE-2026-47654
CVE-2026-45598 CVE-2026-45647 CVE-2026-45648 CVE-2026-45649
CVE-2026-45643 CVE-2026-45644 CVE-2026-45645 CVE-2026-44799
CVE-2026-45640 CVE-2026-45641 CVE-2026-45642 CVE-2026-47288
CVE-2026-47287 CVE-2026-47281 CVE-2026-47284 CVE-2026-42829
CVE-2026-40409 CVE-2026-42828 CVE-2026-45658 CVE-2026-40404
CVE-2026-42824 CVE-2026-45654 CVE-2026-45655 CVE-2026-45656
CVE-2026-45657 CVE-2026-45650 CVE-2026-45653 CVE-2026-47298
CVE-2026-47293 CVE-2026-47292 CVE-2026-47291 CVE-2026-42837
CVE-2026-42836 CVE-2026-42835 CVE-2026-47289 CVE-2026-42969
CVE-2026-42968 CVE-2026-48563 CVE-2026-48562 CVE-2026-48560
CVE-2026-45607 CVE-2026-45608 CVE-2026-45603 CVE-2026-45604
CVE-2026-45605 CVE-2026-45606 CVE-2026-45600 CVE-2026-45601
CVE-2026-45602 CVE-2026-48574 CVE-2026-48575 CVE-2026-50511
CVE-2026-48573 CVE-2026-50512 CVE-2026-48570 CVE-2026-42908
CVE-2026-42907 CVE-2026-42906 CVE-2026-42905 CVE-2026-42909
CVE-2026-42904 CVE-2026-42903 CVE-2026-42902 CVE-2026-48569
CVE-2026-48567 CVE-2026-48568 CVE-2026-48565 CVE-2026-48566
CVE-2026-48583 CVE-2026-42916 CVE-2026-42911 CVE-2026-42910
CVE-2026-45504 CVE-2026-42915 CVE-2026-42914 CVE-2026-42913
CVE-2026-42912 CVE-2026-45500 CVE-2026-45501 CVE-2026-45502
CVE-2026-45503 CVE-2026-48578 CVE-2026-48579 CVE-2026-48576
CVE-2026-45636 CVE-2026-45637 CVE-2026-45638 CVE-2026-45639
CVE-2026-45634 CVE-2026-45635 CVE-2026-33828 CVE-2026-45490
CVE-2026-45491 CVE-2026-45485 CVE-2026-45486 CVE-2026-45487
CVE-2026-32193 CVE-2026-45497 CVE-2026-41108 CVE-2026-50508
CVE-2026-40371 CVE-2026-40376

Change log

Versione Note Data
1.0 Pubblicato il 10-06-2026 10/06/2026

Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità. Può essere visualizzato in versione originale al seguente link

Ultimo aggiornamento

10 Giugno 2026, 09:07