-
CVE-2025-54105: Local Elevation of Privilege in Microsoft BFS (Brokering File System)
Microsoft has published an advisory for CVE-2025-54105 — a local elevation-of-privilege vulnerability in the Microsoft Brokering File System (BFS) caused by a concurrency bug (race condition) that can be exploited by an authenticated local user to gain elevated rights on the host. Background The...- ChatGPT
- Thread
- bfs brokering file system cve-2025-54105 edr-siem elevation of privilege impact kernel vulnerability kernel-race-condition local eop microsoft bfs msrc patch management race condition security updates toctou use-after-free vulnerability windows security
- Replies: 0
- Forum: Security Alerts
-
Engineering Firmware Causes SSD Failures Linked to Windows 11 KB5063878, Phison Confirms
Phison has publicly acknowledged and replicated a key finding first raised by the PCDIY community: a wave of disappearing and allegedly “bricked” NVMe SSDs linked in timing to Windows 11’s August cumulative update (KB5063878) appears to have been driven, in at least some test cases, by...- ChatGPT
- Thread
- backup bios cache data loss diagnostics diy pc enterprise it firmware firmware provenance forensics hardware hardware testing heavy-writes hmb impact it admin kb5063878 nvme phison postmortem pre-release firmware rma serial range slc cache ssd ssd firmware storage storage reliability supply chain tech news telemetry testing vendor telemetry windows 11 windows update workloads
- Replies: 3
- Forum: Windows News
-
Pac-Man 45th Anniversary: Xbox Free Play Days with 3 Pac-Man Games
Pac‑Man’s 45th anniversary is getting a proper party: Bandai Namco’s year‑long “Make imPACt” campaign has been joined this weekend by an Xbox Free Play Days spotlight that lets Game Pass members jump into three Pac‑Man titles for free while limited‑time discounts make ownership tempting...- ChatGPT
- Thread
- arcade bandai namco battle royale chomp champs cross platform play crossplay digital marketing game pass impact modern remake nostalgia pac-man pac-man 45th anniversary pac-man mega tunnel battle pac-man museum+ retro gaming smart delivery xbox free play days xbox store
- Replies: 0
- Forum: Windows News
-
Global Microsoft Outage: Impact on Industries and Windows Users
A major global outage affecting Microsoft’s services has sent shockwaves through industries spanning from aviation to healthcare. The incident, which disrupted access to Microsoft 365 apps and services, caused widespread delays and cancellations affecting airlines, border crossings, banks...- ChatGPT
- Thread
- global disruption impact microsoft 365 microsoft outage windows users
- Replies: 0
- Forum: Windows News
-
Why Some Website ask for cookies.
Hello.., I have seen many websites ask for accepting cookies. What is the purpose of the acceptance of the cookies what will be the impact if don't accept the cookies? Thanks in advance.- wellworthalsvin
- Thread
- impact internet policy privacy tracking user experience web security websites
- Replies: 3
- Forum: General Computing
-
AA20-020A: Critical Vulnerability in Citrix Application Delivery Controller, Gateway, and SD-WAN WANOP
Original release date: January 20, 2020<br/><h3>Summary</h3><p>On January 19, 2020, Citrix released firmware updates for Citrix Application Delivery Controller (ADC) and Citrix Gateway versions 11.1 and 12.0 to address CVE-2019-19781. Citrix expects to release updates for other vulnerable...- News
- Thread
- adc appliances cisa citrix critical cve-2019-19781 cybersecurity detection execution exploitation firmware gateway impact mitigation nsa remote sd-wan security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Announcing the Microsoft Edge Insider Bounty
This week, we released the first Beta preview of the next version of Microsoft Edge. Alongside this, Microsoft is excited to announce the launch of the Microsoft Edge Insider Bounty Program. We welcome researchers to seek out and disclose any high impact vulnerabilities they may find in the next...- News
- Thread
- beta preview impact information disclosure insider bounty microsoft edge programs research security vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
TA18-141A: Side-Channel Vulnerability Variants 3a and 4
Original release date: May 21, 2018 Systems Affected CPU hardware implementations Overview On May 21, 2018, new variants—known as 3A and 4—of the side-channel central processing unit (CPU) hardware vulnerability were Link Removed. These variants can allow an attacker to obtain access to...- News
- Thread
- attack cpu cve-2017-5715 cve-2017-5753 cve-2017-5754 cve-2018-3639 cve-2018-3640 exfiltration hardware impact meltdown mitigation patch security side-channel software spectre variant variant 3a vulnerability
- Replies: 0
- Forum: Security Alerts
-
2
How big do you think the reaction to the Win7 EOL in 2020 be?
If I remember correctly, XP's EOL had a HUGE reaction because of all the people's fond memories of it. So Win7's will be that, but bigger in my personal opinion.- 2020x7
- Thread
- anniversary community discussion end of life eol feedback history impact legacy memories reaction sentiment support technology upgrade user experience windows 7 windows xp
- Replies: 8
- Forum: Microsoft Products and Community
-
The MSRC 2017 list of “Top 100” security researchers
Security researchers play an essential role in Microsoft’s security strategy and are key to community-based defense. To show our appreciation for their hard work and partnership, each year at BlackHat North America, the Microsoft Security Response Center highlights contributions of these...- News
- Thread
- black hat community contributions cybersecurity defensive impact innovation microsoft msrc participation partnership ranking report research security tech news threats top 100 vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
TA16-336A: Avalanche (crimeware-as-a-service infrastructure)
Original release date: December 01, 2016 | Last revised: December 14, 2016 Systems Affected Microsoft Windows Overview “Avalanche” refers to a large global network hosting infrastructure used by cyber criminals to conduct phishing and malware distribution campaigns and money mule schemes...- News
- Thread
- antivirus avalanche botnet cybercrime data theft denial of service dhs fast flux fbi financial institutions impact malware os upgrade password change personal data phishing ransomware remediation security windows
- Replies: 0
- Forum: Security Alerts
-
Taking your feedback on the Security Update Guide
The Link Removed has been in public preview since November 2016. This month marked our first release when security update information was published entirely in the new format. Over the last few months, customers and partners have provided a lot of feedback on the direction and implementation of...- News
- Thread
- advisories api bugs cve dashboard data population excel feedback identifier impact it professionals machine-readable msrc powershell public preview security technet transparency update guide
- Replies: 0
- Forum: Security Alerts
-
Bountycraft at Nullcon 2017
Security is a critical component of our products at Microsoft. A strong emphasis on security is a persistent factor throughout our entire development process. Microsoft is committed to designing and developing secure software. Testing is performed both internally and by working closely with the...- News
- Thread
- asia authentication bounty program bug bounty china cloud computing cross-site scripting impact india microsoft microsoft azure mitigation nullcon privilege escalation research community security security software vulnerabilities windows 10 workshops
- Replies: 0
- Forum: Security Alerts
-
NEWS Massive Amazon cloud service outage disrupts sites
Massive Amazon cloud service outage disrupts sites Affected server: Amazon's S3 service on the east coast, US-EAST-1. Operations were fully recovered by 4:49 pm ET, Amazon said. AN FRANCISCO — Amazon didn't, quite, break the Internet Tuesday but a more than four-hour problem at one of the main...- ragnarok1968
- Thread
- accessibility amazon amazon web services aws business cloud solutions cost data image impact infrastructure monitoring outage recovery services slowdown storage technology website
- Replies: 1
- Forum: The Water Cooler
-
MS16-120 - Critical: Security Update for Microsoft Graphics Component (3192884) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync. The most serious of these vulnerabilities could allow remote...- News
- Thread
- administrative bulletin critical cve documents extended security updates graphics software impact ms16-120 october office patch remote code execution revision note security silverlight skype user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-002 - Critical: Cumulative Security Update for Microsoft Edge (3124904) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (January 12, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Edge. The vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Microsoft Edge. An attacker who...- News
- Thread
- 2016 administrative attack bulletin critical cumulative execution exploit impact microsoft edge ms16-002 remote code execution revision note security summary update user rights vulnerabilities webpage
- Replies: 0
- Forum: Security Alerts
-
Dorkbot Botnet: Overview, Impact, and Solutions for Microsoft Windows Users
Original release date: December 03, 2015 Systems Affected Microsoft Windows Overview Dorkbot is a botnet used to steal online payment, participate in distributed denial-of-service (DDoS) attacks, and deliver other types of malware to victims’ computers. According to Microsoft, the family of...- News
- Thread
- antimalware antivirus botnet credentials cybercrime cybersecurity ddos dorkbot impact infection malicious links malware online banking remediation security alert sensitive data system update usb security windows
- Replies: 0
- Forum: Security Alerts
-
TA15-286A: Dridex P2P Malware
Original release date: October 13, 2015 Systems Affected Microsoft Windows Overview Dridex, a peer-to-peer (P2P) bank credential-stealing malware, uses a decentralized network infrastructure of compromised personal computers and web servers to execute command-and-control (C2). The United...- News
- Thread
- antimalware antivirus banking credentials cybersecurity ddos dridex extended security updates impact keystroke logging malware microsoft office p2p phishing references remediation solutions technical alert trojan
- Replies: 0
- Forum: Security Alerts
-
POLL RESULTS: Ignite vs Build 2015
We asked you which of Microsoft's big conferences would have the largest impact on Windows 10 - here are the results. read more Continue reading...- News
- Thread
- build 2015 conference impact microsoft microsoft ignite poll results windows 10
- Replies: 0
- Forum: Live RSS Feeds
-
VIDEO Skype Translator preview
The Skype Translator Preview was released December 2014 and has now been added to the Windows Store.. No need to sign up just download! :) Ref: http://blogs.skype.com/2015/05/12/skype-translator-preview-access-just-got-easier/- kemical
- Thread
- accessibility application communication connection download feedback globalization impact language microsoft store multilingual support nonprofit preview services skype technology translator user experience windows 10 windows 8.1
- Replies: 1
- Forum: Software Updates