ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Two Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-32201CVE-2026-33825CVE-2026-33824

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32201
Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server

Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown.

Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity.

6.543% KEV
  • Microsoft SharePoint Server
masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed
CVE-2026-33824
Unauthenticated Double-Free RCE in Microsoft Windows IKE Extension

A double-free memory-corruption flaw (CWE-415) in the Microsoft Windows Internet Key Exchange (IKE) service extension allows a remote, unauthenticated attacker to trigger the bug with crafted network traffic, with no privileges or user interaction required. Successful exploitation yields remote code execution with full system impact, reflected in the critical 9.8 CVSS score (high confidentiality, integrity, and availability). The vulnerable IKE component is present in Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, and 2022 (including 23H2), which ship it as a built-in feature. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-18, and security reporting confirms it is being actively exploited in the wild, though ransomware use is not yet confirmed. No public proof-of-concept is known, but the high EPSS score (72.7%, 99th percentile) signals a very strong likelihood of imminent or ongoing exploitation.

Do: Apply Microsoft's security updates for CVE-2026-33824 to all affected Windows 10, Windows 11, and Windows Server releases, prioritizing internet-exposed systems where IKE/VPN is reachable (UDP 500/4500), per BOD 26-04 requirements. Organizations unable to patch promptly should restrict or discontinue use of exposed IKE/VPN services on affected hosts until updated. Triage VPN endpoints and remote-access servers for crashes or suspicious IKE traffic given confirmed in-the-wild exploitation.

9.873% KEV
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 21H2
  • +9 more
masswell over 1B Windows devices include the built-in IKE extension; internet-exposed VPN/IKE endpoints plausibly number in the hundreds of thousands
CVE-2026-33825
Local Privilege Escalation in Microsoft Defender Antimalware Platform

CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting.

Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately.

7.87% KEV ransomware
  • Microsoft Defender Antimalware Platform
masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows)
Full article395 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft published a higher-than-usual list of fixes for CVEs as part of its monthly Patch Tuesday update round yesterday, including two zero-day vulnerabilities.

One of these, CVE-2026-32201, is being actively exploited in the wild.

It is described as a server spoofing vulnerability in SharePoint whereby improper input validation allows an unauthorized attacker to perform spoofing over a network.

“By exploiting this flaw, an attacker can manipulate how information is presented to users, potentially tricking them into trusting malicious content. While the direct impact on data is limited, the ability to deceive users makes this a powerful tool for broader attacks,” explained Action1 president, Mike Walters.

“It can be used to deceive employees, partners, or customers by presenting falsified information within trusted SharePoint environments. This CVE can enable phishing attacks, unauthorized data manipulation, or social engineering campaigns that lead to further compromise.”

Read more on Patch Tuesday: Microsoft Fixes Two Publicly Disclosed Zero-Days.

The second zero-day has been publicly disclosed but not exploited at this time.

CVE-2026-33825 is an elevation of privilege (EoP) vulnerability in Microsoft Defender that could enable a threat actor to gain system-level access.

Jack Bicer, director of vulnerability research at Action1, warned that the CVE could be chained with others in real-world attacks.

“CVE-2026-33825 significantly increases risk in environments where attackers have already gained a foothold,” he added.

“Once exploited, it allows full control over endpoints, enabling data exfiltration, disabling security tools, and lateral movement across networks. Even environments with strong perimeter defenses are at risk if internal systems are compromised.”

EoP Bugs Dominate April

In fact, EoP vulnerabilities are by far the largest category of CVEs this month, amounting to 93 flaws. Information disclosure (21), remote code execution (20) and security feature bypass (13) comprise the next-largest categories by volume.

Walters urged sysadmins to also look at CVE-2026-33824. With a CVSS score of 9.8, the remote code execution flaw is the most dangerous on paper this month and impacts the Windows Internet Key Exchange (IKE) service.

Threat actors could exploit the vulnerability remotely by sending specially crafted network packets, with internet-facing IKEv2 systems particularly at risk, he said.

“This issue poses a serious threat to enterprise environments, especially those relying on VPN or IPsec for secure communications,” Walters continued. “Successful exploitation can result in complete system compromise, allowing attackers to steal sensitive data, disrupt operations, or move laterally across the network.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-two-zerodays-april-patch/