Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Confirms Two Azure Bot Service Elevation-of-Privilege Flaws, Urges Immediate Patching
Security teams responsible for Azure Bot Service deployments are grappling with a double-barreled set of improper authorization vulnerabilities that could let unauthenticated attackers hijack cloud...
Microsoft Confirms Windows August 2025 Updates Break Silent MSI Repairs, Trigger UAC Prompts
Microsoft has acknowledged a compatibility regression introduced by the August 12, 2025 cumulative security updates for Windows, which causes unexpected User Account Control (UAC) elevation prompts...
ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers
In June 2025, ESET researchers unearthed a previously unknown threat actor they call GhostRedirector, which had compromised at least 65 Windows servers around the globe. The attackers deployed two...
KB5063878 Forces UAC Prompts on Non-Admins, Triggering MSI Error 1730 Across Enterprise Apps
Microsoft’s August 12, 2025 cumulative update for Windows 11 24H2, KB5063878 (OS Build 26100.4946), has inadvertently stalled critical enterprise applications for standard users. The patch,...
GE Vernova Issues Urgent Patch for CIMPLICITY DLL Hijacking Flaw Rated CVSS 7.0
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an advisory detailing a dangerous privilege escalation vulnerability in GE Vernova’s CIMPLICITY HMI/SCADA platform....
Schneider Electric Patches Saitel DR RTU Flaw CVE-2025-8453 — DP RTU Fix Still Pending
Schneider Electric has shipped a firmware remedy for its Saitel DR Remote Terminal Units to plug a privilege management hole tracked as CVE-2025-8453, while a corresponding fix for the Saitel DP line...
CERT-In Urges Immediate Patching of Critical Microsoft Edge, Windows Server, and Azure Databricks Flaws to Avert Ransomware
India's Computer Emergency Response Team (CERT-In) has issued a high-severity advisory warning organizations and individuals to urgently patch a range of Microsoft products, including the Edge...
CERT-In Warns: Patch Windows and Cloud Now as Microsoft Fixes 111 Vulnerabilities, Including Kerberos Zero-Day
India's Computer Emergency Response Team (CERT-In) has issued a high-severity advisory urging organizations and home users to apply Microsoft's latest security updates immediately. The warning...
CISA Flags Urgent Patches for Exploited Citrix Session Recording and Git Flaws
The Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2025, signaling active exploitation of flaws...
Critical Copilot Audit Flaw Fixed Silently as Governance Issues Mount
Microsoft has patched a critical flaw in Microsoft 365 Copilot that allowed attackers to access and summarize enterprise files without leaving any trace in audit logs—and did so without notifying...
CVE-2025-53763: Microsoft Flags Azure Databricks Privilege Escalation Flaw, Urges Immediate Defensive Actions
Microsoft has disclosed a new privilege escalation vulnerability in Azure Databricks, tracked as CVE-2025-53763, which could allow an attacker with network access to elevate their privileges within...
Patch Now: Microsoft's netbt.sys Kernel Flaw (CVE-2025-55230/47996) Grants Attackers Full Control
A local elevation-of-privilege flaw in the Windows MBT Transport driver—the kernel component behind NetBIOS over TCP/IP—can hand attackers full SYSTEM rights, and while Microsoft’s July 2025...