Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Posted on June 10, 2026 By safdargal12 No Comments on Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed
Blog

Tuesday’s patch bundle also fixed MiniPlasma, a separate vulnerability disclosed by Nightmare Eclipse. Microsoft said in an email that the vulnerability is tracked as CVE-2020-17103, a vulnerability Microsoft first fixed six years ago. That means MiniPlasma was the result of a regression or an incomplete patch in its initial form. The company is in the process of updating Tuesday’s bulletin to note the republication.

Microsoft has yet to release patches for other vulnerabilities disclosed by Nightmare Eclipse. The company did provide manual instructions for mitigating YellowKey, a vulnerability that allows attackers to defeat Bitlocker full-disk encryption. That could be a boon when attackers have physical access to a device (the precise scenario Bitlocker is designed to protect against). The company has yet to fix the underlying cause of the vulnerability.

The status of other vulnerabilities disclosed by Nightmare Eclipse are also unclear at the moment. The researcher named one vulnerability, present in Windows Defender RedSun. Another, named BlueHammer, is also a local privilege escalation flaw that provides SYSTEM rights.

Over the past few months, Nightmare Eclipse has taken multiple potshots at Microsoft. The specific criticisms remain unclear, but many make references to complaints about the company’s vulnerability disclosure program. Microsoft, in turn, has publicly railed against the researcher for “not responsibly” disclosing the vulnerabilities and made a vailed reference to the possibility of pursuing legal action. After a public backlash, Microsoft later relented and vowed no such legal action would occur.

On Tuesday, Nightmare Eclipse published exploit code for a new Windows vulnerability. It’s a race condition that targets Defender.

Tuesday’s patch batch included fixes for roughly 200 vulnerabilities. Notwithstanding the appearance that MiniPlasma was fixed, two of them were also confirmed as zero-days.

Post updated to include information Microsoft provided after initial publication of this post.



Source link

Post Views: 2

Post navigation

❮ Previous Post: The Evolution of ‘More Like This’
Next Post: Today’s NYT Mini Crossword Answers for June 10 ❯

You may also like

The Agent Harness Belongs Outside the Sandbox
Blog
The Agent Harness Belongs Outside the Sandbox
May 2, 2026
The Future of Apple Watch AI Isn’t a Chatbot. It’s a Coach
Blog
The Future of Apple Watch AI Isn’t a Chatbot. It’s a Coach
June 3, 2026
My go-to electric screwdriver is on sale for over 50 percent off today
Blog
My go-to electric screwdriver is on sale for over 50 percent off today
April 11, 2026
A nasty Pixel Fold bug is making one screen stop working
Blog
A nasty Pixel Fold bug is making one screen stop working
May 22, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • The App Store is going to add subscription bundles soon
  • Top Lucid Motors executive departs amid new CEO’s leadership shakeup
  • Today’s NYT Mini Crossword Answers for June 10
  • Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed
  • The Evolution of ‘More Like This’

Recent Comments

  1. Last Chance for Big Savings on TechCrunch Disrupt 2026 Tickets – Artiverse on 5 days left: Save up to $410 on Disrupt 2026 passes

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown