security vulnerabilities

  1. What CVSS S:C Means for CVE-2026-27928: Changed Scope and Tenant Cross-Access

    In CVSS terms, S:C means the vulnerability has a changed scope: a successful exploit can cross a security boundary and affect something outside the vulnerable component’s own authorization context. In plain English, the attacker is not just influencing the Windows Hello component itself; they...
  2. KB5084597: Windows RRAS Hotpatch Fix for RCE Flaws in Enterprise

    Microsoft’s out‑of‑band hotpatch KB5084597, quietly deployed in mid‑March 2026, closes a cluster of critical remote‑code‑execution flaws in the Windows Routing and Remote Access Service (RRAS) management tool — and it does so using Microsoft’s hotpatch mechanism so eligible enterprise endpoints...
  3. Windows 11 KB5074109 Removes Four Legacy Modem Drivers — Security vs Compatibility

    Microsoft’s January cumulative for Windows 11 deliberately removed four legacy modem drivers from the in‑box image—breaking modem-based telephony and POS appliances for a measurable subset of users—and the only immediate workaround for most affected systems is to uninstall KB5074109 and pause...
  4. Windows 11 KB5074109 Boot Failures and WinRE Recovery Guide

    Microsoft released its January cumulative for Windows 11 (KB5074109) on January 13, 2026 — and within days a series of serious regressions began surfacing, from brief black screens on some Nvidia-equipped machines to full startup failures that print UNMOUNTABLE_BOOT_VOLUME (Stop Code 0xED) and...