Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #3
New Windows NCSI proxy authentication flaw detailed by researchers
Original: Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: https:// pgj11.com/posts/Windo
Security researchers have published a two-part technical write-up of a Windows vulnerability tracked as ZDI-26-708, described as a cross-context proxy authentication coercion in the Network Connectivity Status Indicator (NCSI). The disclosure is circulating among security professionals sharing the detailed analysis. Details on affected versions and patches remain unclear from the discussion so far.
Why now: A newly disclosed Windows security vulnerability with in-depth technical write-ups is drawing attention from the cybersecurity community.
MicrosoftWindowsNCSIZero Day Initiative
Evidence
- Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: https:// pgj11.com/posts/Windows-NCSI-P roxy-Auth-Coercion-Part-1/ Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 2: https://… · alexandreborges@infosec.exchange · 2
- Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: https:// pgj11.com/posts/Windows-NCSI-P roxy-Auth-Coercion-Part-1/ Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 2: https://… · alexandreborges · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/363634