Three Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-31096 | An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit this to elevate privileges from a medium-integrity process to SYSTEM. This can also be used to bypass kernel-level protections such as AV or PPL, because exploit code runs with high-integrity privileges and can be used in coordinated BYOVD (bring your own vulnerable driver) ransomware campaigns. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2026-20805 | Local Information Disclosure in Microsoft Desktop Windows Manager (CVE-2026-20805) CVE-2026-20805 is an information disclosure flaw (CWE-200) in Desktop Windows Manager (DWM) that exposes sensitive information to an unauthorized actor. An authorized attacker with local access and low privileges can trigger the flaw without user interaction and read sensitive data to which they should not have access. All supported Windows client versions from Windows 10 1607 through Windows 11 25H2 and Windows Server from 2012 through 2022 23H2 are affected, meaning essentially the entire installed Windows estate. The flaw was fixed in Microsoft's January 2026 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-13, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available. Do: Deploy the January 2026 Microsoft security updates (Patch Tuesday) for every affected Windows 10/11 client and Windows Server release, prioritizing internet-facing and multi-user systems. Federal agencies must apply the updates per BOD 22-01 timelines following the KEV listing on 2026-01-13; other organizations should treat this as a priority patch given confirmed in-the-wild exploitation. After patching, review local account activity on Windows endpoints for signs of low-privileged information gathering, and note that patching is the primary mitigation since the flaw requires only local access. | 5.5 | 5% | KEV PoC |
| masshundreds of millions of Windows client devices plus millions of Windows Server instances across all listed versions | |
| CVE-2026-21265 | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates. NVD description · AI analysis pending | 6.4 | 1% |
| — |
Full article464 words · extracted from infosecurity-magazine.com · click to collapse
It’s set to be a busy month for system administrators after Microsoft released security updates to fix over 100 CVEs yesterday, including one being actively exploited.
CVE-2026-20805 is one of three zero-day bugs fixed on the first Patch Tuesday of 2026 – the other two being publicly disclosed but not yet used in attacks.
It’s listed as an information disclosure vulnerability in the Desktop Window Manager.
“This CVE quietly leaks sensitive memory details, giving attackers the inside knowledge they need to weaken system protections and prepare for deeper compromise,” explained Action1 director of vulnerability research, Jack Bicer.
“An authorized local attacker can trigger the flaw to disclose a section address from a remote ALPC port residing in user-mode memory. Although no data modification or denial-of-service occurs, the exposed memory information can undermine address space layout randomization (ASLR) and other defenses, making additional exploits more reliable.”
Read more on Patch Tuesday: Microsoft Fixes Three Zero-Days in Final Patch Tuesday of 2025
The other two zero-days include CVE-2026-21265: a security feature bypass vulnerability related to secure boot certificate expiration.
This relates to the expiration of Microsoft’s original 2011 Root of Trust certificates this year.
“These certificates sign nearly every Windows bootloader since Windows 8, and they are set to expire in June and October 2026,” explained Ryan Braunstein, security manager at Automox.
“If you bought a motherboard or computer between 2012 and 2025, CVE-2026-21265 applies to you.”
He claimed that, among other things, hackers could chain the CVE with others to prevent systems from updating their forbidden signature database before deploying a rootkit.
“This is not a vulnerability you can patch once and forget,” Braunstein warned.
“It requires an audit of your entire hardware environment and coordination between OS and firmware updates. Some BIOS updates may require manual acceptance of the new UEFI certificates rolled out in 2023.”
A Zero Day From 2023
The third zero-day is CVE-2023-31096: an elevation of privilege (EoP) in the Agere Modem driver that ships with some Windows versions.
“This vulnerability was originally published via MITRE over two years ago, along with a credible public writeup by the original researcher. Today’s Windows patches remove agrsm64.sys and agrsm.sys,” explained Rapid7 lead software engineer, Adam Barnett.
“All three modem drivers were originally developed by the same now-defunct third party and have been included in Windows for decades. These driver removals will pass unnoticed for most people, but you might find active modems still in a few contexts, including some industrial control systems.”
Among the 114 CVEs patched by Microsoft this month, 57 are EoP, while a further 22 are remote code execution and 22 are classed as information disclosure. Just eight are classed as critical, although – as always – context matters and will vary for each organization.
Image credit: CHERRY.JUICE / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-three-zerodays-busy/