started · updated
Microsoft software faces critical vulnerability chains
Security researchers have identified two significant vulnerability chains targeting Microsoft software.
One exploit, dubbed ‘Download More RAM,’ targets the Microsoft Windows kernel and hypervisor. Researchers from the University of Birmingham and SeriSec found that this chain of three vulnerabilities can bypass Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI). By undermining hardware-backed security and memory isolation, attackers can execute kernel-mode code and use automated scripts to disable Microsoft Defender and other endpoint detection and response (EDR) solutions. The exploit can be delivered via the ‘PolitePaul’ service, allowing for remote execution with minimal user interaction.
Separately, a vulnerability chain affecting Microsoft System Center Configuration Manager (SCCM) has been disclosed. This flaw allows an attacker with standard Active Directory domain user credentials to execute malicious code remotely on an SCCM primary site server. The attack chain involves an authorization issue in the AdminService REST API, a weakness in signature validation for CAB archives, and a path traversal flaw known as ‘CabSlip.’ While Microsoft has released a fix for the initial authorization issue (CVE-2026-47301), researchers note that other weaknesses in the chain remain unpatched, with further fixes expected in late 2026.