Marcowy Wtorek Microsoftu 2026. (P26-095)

cert.pse-online.pl 2 tygodni temu

W marcu 2026 Microsoft opublikował comiesięczny zestaw aktualizacji bezpieczeństwa, w ramach którego naprawiono 79 podatności, z czego 2 stanowiły publicznie ujawnione luki typu zero‑day. Aktualizacje objęły system Windows oraz usługi i produkty takie jak Microsoft Office, SQL Server, .NET, Azure czy komponenty systemowe.

Najważniejsze elementy aktualizacji

  • 2 luki zero‑day:
    • CVE‑2026‑21262 – luka podnoszenia uprawnień w SQL Server, umożliwiająca uzyskanie praw SQLAdmin.
    • CVE‑2026‑26127 – podatność typu Denial of Service w .NET, wywoływana przez odczyt poza zakresem.
  • 3 luki o krytycznym priorytecie, z czego dwie umożliwiają zdalne wykonanie kodu (RCE) w Microsoft Office, a jedna dotyczy wycieku informacji (m.in. w Excelu).
TytułNumer CVEOpisKrytyczność
.NETCVE-2026-26131.NET Elevation of Privilege VulnerabilityWysoka
.NETCVE-2026-26127.NET Denial of Service VulnerabilityWysoka
Active Directory Domain ServicesCVE-2026-25177Active Directory Domain Services Elevation of Privilege VulnerabilityWysoka
ASP.NET CoreCVE-2026-26130ASP.NET Core Denial of Service VulnerabilityWysoka
Azure ArcCVE-2026-26141Hybrid Worker Extension (Arc-enabled Windows VMs) Elevation of Privilege VulnerabilityWysoka
Azure Compute GalleryCVE-2026-23651Microsoft ACI Confidential Containers Elevation of Privilege VulnerabilityKrytyczna
Azure Compute GalleryCVE-2026-26124Microsoft ACI Confidential Containers Elevation of Privilege VulnerabilityKrytyczna
Azure Compute GalleryCVE-2026-26122Microsoft ACI Confidential Containers Information Disclosure VulnerabilityKrytyczna
Azure Entra IDCVE-2026-26148Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege VulnerabilityWysoka
Azure IoT ExplorerCVE-2026-26121Azure IOT Explorer Spoofing VulnerabilityWysoka
Azure IoT ExplorerCVE-2026-23662Azure IoT Explorer Information Disclosure VulnerabilityWysoka
Azure IoT ExplorerCVE-2026-23661Azure IoT Explorer Information Disclosure VulnerabilityWysoka
Azure IoT ExplorerCVE-2026-23664Azure IoT Explorer Information Disclosure VulnerabilityWysoka
Azure Linux Virtual MachinesCVE-2026-23665Linux Azure Diagnostic extension (LAD) Elevation of Privilege VulnerabilityWysoka
Azure MCP ServerCVE-2026-26118Azure MCP Server Tools Elevation of Privilege VulnerabilityWysoka
Azure Portal Windows Admin CenterCVE-2026-23660Windows Admin Center in Azure Portal Elevation of Privilege VulnerabilityWysoka
Azure Windows Virtual Machine AgentCVE-2026-26117Arc Enabled Servers – Azure Connected Machine Agent Elevation of Privilege VulnerabilityWysoka
Broadcast DVRCVE-2026-23667Broadcast DVR Elevation of Privilege VulnerabilityWysoka
Connected Devices Platform Service (Cdpsvc)CVE-2026-24292Windows Connected Devices Platform Service Elevation of Privilege VulnerabilityWysoka
GitHub Repo: zero-shot-scfoundationCVE-2026-23654GitHub: Zero Shot SCFoundation Remote Code Execution VulnerabilityWysoka
MarinerCVE-2026-23235f2fs: fix out-of-bounds access in sysfs attribute read/writeWysoka
MarinerCVE-2026-23234f2fs: fix to avoid UAF in f2fs_write_end_io()Wysoka
MarinerCVE-2026-3713pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflowŚrednia
MarinerCVE-2026-23237platform/x86: classmate-laptop: Add missing NULL pointer checksŚrednia
MarinerCVE-2026-26017CoreDNS ACL BypassWysoka
MarinerCVE-2026-26018CoreDNS Loop Detection Denial of Service VulnerabilityWysoka
MarinerCVE-2026-2297SourcelessFileLoader does not use io.open_code()Średnia
MarinerCVE-2026-0038In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Wysoka
MarinerCVE-2026-27601Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attackWysoka
MarinerCVE-2026-23236fbdev: smscufx: properly copy ioctl memory to kernelspaceŚrednia
MarinerCVE-2026-23865An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.Średnia
MarinerCVE-2025-71238scsi: qla2xxx: Fix bsg_done() causing double freeŚrednia
MarinerCVE-2026-3338PKCS7_verify Signature Validation Bypass in AWS-LCWysoka
MarinerCVE-2026-23231netfilter: nf_tables: fix use-after-free in nf_tables_addchain()Wysoka
MarinerCVE-2026-3381Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlibKrytyczna
MarinerCVE-2026-0031In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Wysoka
MarinerCVE-2026-23238romfs: check sb_set_blocksize() return valueŚrednia
MarinerCVE-2026-3494MariaDB Server Audit Plugin Comment Handling BypassŚrednia
MarinerCVE-2026-3336PKCS7_verify Certificate Chain Validation Bypass in AWS-LCWysoka
MarinerCVE-2026-0032In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Wysoka
Microsoft AuthenticatorCVE-2026-26123Microsoft Authenticator Information Disclosure VulnerabilityWysoka
Microsoft Brokering File SystemCVE-2026-25167Microsoft Brokering File System Elevation of Privilege VulnerabilityWysoka
Microsoft Devices Pricing ProgramCVE-2026-21536Microsoft Devices Pricing Program Remote Code Execution VulnerabilityKrytyczna
Microsoft Edge (Chromium-based)CVE-2026-3544Chromium: CVE-2026-3544 Heap buffer overflow in WebCodecsNieznana
Microsoft Edge (Chromium-based)CVE-2026-3540Chromium: CVE-2026-3540 Inappropriate implementation in WebAudioNieznana
Microsoft Edge (Chromium-based)CVE-2026-3536Chromium: CVE-2026-3536 Integer overflow in ANGLENieznana
Microsoft Edge (Chromium-based)CVE-2026-3538Chromium: CVE-2026-3538 Integer overflow in SkiaNieznana
Microsoft Edge (Chromium-based)CVE-2026-3545Chromium: CVE-2026-3545 Insufficient data validation in NavigationNieznana
Microsoft Edge (Chromium-based)CVE-2026-3541Chromium: CVE-2026-3541 Inappropriate implementation in CSSNieznana
Microsoft Edge (Chromium-based)CVE-2026-3543Chromium: CVE-2026-3543 Inappropriate implementation in V8Nieznana
Microsoft Edge (Chromium-based)CVE-2026-3539Chromium: CVE-2026-3539 Object lifecycle issue in DevToolsNieznana
Microsoft Edge (Chromium-based)CVE-2026-3542Chromium: CVE-2026-3542 Inappropriate implementation in WebAssemblyNieznana
Microsoft Graphics ComponentCVE-2026-25169Windows Graphics Component Denial of Service VulnerabilityWysoka
Microsoft Graphics ComponentCVE-2026-25180Windows Graphics Component Information Disclosure VulnerabilityWysoka
Microsoft Graphics ComponentCVE-2026-25168Windows Graphics Component Denial of Service VulnerabilityWysoka
Microsoft Graphics ComponentCVE-2026-23668Windows Graphics Component Elevation of Privilege VulnerabilityWysoka
Microsoft OfficeCVE-2026-26110Microsoft Office Remote Code Execution VulnerabilityKrytyczna
Microsoft OfficeCVE-2026-26113Microsoft Office Remote Code Execution VulnerabilityKrytyczna
Microsoft OfficeCVE-2026-26134Microsoft Office Elevation of Privilege VulnerabilityWysoka
Microsoft Office ExcelCVE-2026-26144Microsoft Excel Information Disclosure VulnerabilityKrytyczna
Microsoft Office ExcelCVE-2026-26109Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office ExcelCVE-2026-26108Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office ExcelCVE-2026-26107Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office ExcelCVE-2026-26112Microsoft Excel Remote Code Execution VulnerabilityWysoka
Microsoft Office SharePointCVE-2026-26105Microsoft SharePoint Server Spoofing VulnerabilityWysoka
Microsoft Office SharePointCVE-2026-26114Microsoft SharePoint Server Remote Code Execution VulnerabilityWysoka
Microsoft Office SharePointCVE-2026-26106Microsoft SharePoint Server Remote Code Execution VulnerabilityWysoka
Microsoft Semantic Kernel Python SDKCVE-2026-26030GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerableWysoka
Payment Orchestrator ServiceCVE-2026-26125Payment Orchestrator Service Elevation of Privilege VulnerabilityKrytyczna
Push Message Routing ServiceCVE-2026-24282Push message Routing Service Elevation of Privilege VulnerabilityWysoka
Role: Windows Hyper-VCVE-2026-25170Windows Hyper-V Elevation of Privilege VulnerabilityWysoka
SQL ServerCVE-2026-21262SQL Server Elevation of Privilege VulnerabilityWysoka
SQL ServerCVE-2026-26116SQL Server Elevation of Privilege VulnerabilityWysoka
SQL ServerCVE-2026-26115SQL Server Elevation of Privilege VulnerabilityWysoka
System Center Operations ManagerCVE-2026-20967System Center Operations Manager (SCOM) Elevation of Privilege VulnerabilityWysoka
Windows Accessibility Infrastructure (ATBroker.exe)CVE-2026-25186Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure VulnerabilityWysoka
Windows Accessibility Infrastructure (ATBroker.exe)CVE-2026-24291Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege VulnerabilityWysoka
Windows Ancillary Function Driver for WinSockCVE-2026-25179Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWysoka
Windows Ancillary Function Driver for WinSockCVE-2026-24293Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWysoka
Windows Ancillary Function Driver for WinSockCVE-2026-25176Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWysoka
Windows Ancillary Function Driver for WinSockCVE-2026-25178Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWysoka
Windows App InstallerCVE-2026-23656Windows App Installer Spoofing VulnerabilityWysoka
Windows Authentication MethodsCVE-2026-25171Windows Authentication Elevation of Privilege VulnerabilityWysoka
Windows Bluetooth RFCOM Protocol DriverCVE-2026-23671Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege VulnerabilityWysoka
Windows Device Association ServiceCVE-2026-24296Windows Device Association Service Elevation of Privilege VulnerabilityWysoka
Windows Device Association ServiceCVE-2026-24295Windows Device Association Service Elevation of Privilege VulnerabilityWysoka
Windows DWM Core LibraryCVE-2026-25189Windows DWM Core Library Elevation of Privilege VulnerabilityWysoka
Windows Extensible File AllocationCVE-2026-25174Windows Extensible File Allocation Table Elevation of Privilege VulnerabilityWysoka
Windows File ServerCVE-2026-24283Multiple UNC Provider Kernel Driver Elevation of Privilege VulnerabilityWysoka
Windows GDICVE-2026-25190GDI Remote Code Execution VulnerabilityWysoka
Windows GDI+CVE-2026-25181GDI+ Information Disclosure VulnerabilityWysoka
Windows KerberosCVE-2026-24297Windows Kerberos Security Feature Bypass VulnerabilityWysoka
Windows KernelCVE-2026-26132Windows Kernel Elevation of Privilege VulnerabilityWysoka
Windows KernelCVE-2026-24289Windows Kernel Elevation of Privilege VulnerabilityWysoka
Windows KernelCVE-2026-24287Windows Kernel Elevation of Privilege VulnerabilityWysoka
Windows MapUrlToZoneCVE-2026-23674MapUrlToZone Security Feature Bypass VulnerabilityWysoka
Windows Mobile BroadbandCVE-2026-24288Windows Mobile Broadband Driver Remote Code Execution VulnerabilityWysoka
Windows NTFSCVE-2026-25175Windows NTFS Elevation of Privilege VulnerabilityWysoka
Windows Performance CountersCVE-2026-25165Performance Counters for Windows Elevation of Privilege VulnerabilityWysoka
Windows Print Spooler ComponentsCVE-2026-23669Windows Print Spooler Remote Code Execution VulnerabilityWysoka
Windows Projected File SystemCVE-2026-24290Windows Projected File System Elevation of Privilege VulnerabilityWysoka
Windows Resilient File System (ReFS)CVE-2026-23673Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2026-26111Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2026-25173Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWysoka
Windows Routing and Remote Access Service (RRAS)CVE-2026-25172Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityWysoka
Windows Shell Link ProcessingCVE-2026-25185Windows Shell Link Processing Spoofing VulnerabilityWysoka
Windows SMB ServerCVE-2026-26128Windows SMB Server Elevation of Privilege VulnerabilityWysoka
Windows SMB ServerCVE-2026-24294Windows SMB Server Elevation of Privilege VulnerabilityWysoka
Windows System Image ManagerCVE-2026-25166Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution VulnerabilityWysoka
Windows Telephony ServiceCVE-2026-25188Windows Telephony Service Elevation of Privilege VulnerabilityWysoka
Windows Universal Disk Format File System Driver (UDFS)CVE-2026-23672Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityWysoka
Windows Win32KCVE-2026-24285Win32k Elevation of Privilege VulnerabilityWysoka
WinlogonCVE-2026-25187Winlogon Elevation of Privilege VulnerabilityWysoka

Źródło: https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/

Idź do oryginalnego materiału