ZeroHour
Product

Azure Machine Learning

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft patched 18 elevation-of-privilege and information-disclosure vulnerabilities across Azure and Copilot products; all fixed server-side with no exploitation observed.

Microsoft on Thursday released patches for 18 vulnerabilities spanning its Azure cloud portfolio and Copilot-branded AI products, with elevation-of-privilege flaws affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Dataverse, and Microsoft 365 Copilot, among others. Information-disclosure bugs were fixed in Copilot, Microsoft 365 Copilot, Copilot Business Chat, and Azure Machine Learning, plus one Azure Portal spoofing flaw. Microsoft rated all 18 critical, though CVSS scores indicate high or medium for some; none were flagged as exploited and all fixes were implemented server-side, requiring no customer action. Separately, Microsoft patched a Windows privilege-escalation flaw tracked as CVE-2026-85921, deemed less likely to be exploited, after fixing a record 970 vulnerabilities in the latest Patch Tuesday.

SecurityWeekupdated · 3h agofirst · 6h agoAdvisory 3 sourcesCVE-2026-85921

Related CVEs

  • Double Free in Windows Secure Kernel Mode Enables Local Privilege Escalation
    CVE-2026-85921 is a double free flaw (CWE-415) in Windows Secure Kernel Mode, the hypervisor-based component that underpins Virtualization-Based Security (VBS) on Windows clients and servers. It is triggered locally by an already-authorized attacker who holds high privileges on the machine (per the CVSS vector, privileges required: high), and successful exploitation lets them elevate privileges across a security boundary — escaping the isolation that Secure Kernel is meant to enforce — with high impact on confidentiality, integrity, and availability. In practice, an attacker with administrative code execution on a VBS-enabled host could leverage the bug to break out of or subvert the secure-kernel boundary and gain deeper, SYSTEM/hypervisor-adjacent control of the system. Any Windows deployment running Secure Kernel Mode (i.e., with VBS/HVCI or Hyper-V-based isolation enabled) is in scope. As of this writing there is no known public proof of concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
    · Microsoft Windows Secure Kernel Modemass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.