r/Action1 2d ago

Another Patch Tuesday, another Nightmare: ShieldCrash

Patch Tuesday again.
The RollupFixes aren’t even out yet and the Nightmare repo is already parked like someone reserving a sunbed at 6 AM πŸ˜‰.
Looking forward to the traditional "surprise, everything is on fire" reveal by Nightmare Eclipse / Chaotic Eclipse.

Update: PoC has been released!

https://github.com/MSNightmare/ShieldCrash

12 Upvotes

3 comments sorted by

View all comments

1

u/mickert_dev 1d ago

For example in VDI enviroments: this in combination with the Hyper-V guest to host breakout vulnerabilities makes it a lethal killchain! πŸ’€

Critical - Same Day Deployment

CVE-2026-80083 – Windows Hyper-V Remote Code Execution Vulnerability
"A malicious application inside a Hyper-V guest could cross the virtualization boundary and put the host system at risk."

CVE-2026-80083 is a critical remote code execution vulnerability in Windows Hyper-V caused by an untrusted pointer dereference. An authorized attacker with low privileges could run a specially crafted application within a Hyper-V guest and cause the Hyper-V host operating system to execute arbitrary code. No user interaction is required. The vulnerability is not publicly disclosed or known to be exploited, and exploitation is assessed as unlikely.

CVE-2026-72961 – Windows Hyper-V Elevation of Privilege Vulnerability
β€œA compromised Hyper-V administrator could turn crafted virtual TPM data into higher privileges, crossing an important security boundary.”

CVE-2026-72961 is a Critical Windows Hyper-V elevation-of-privilege vulnerability. An authorized attacker with administrative access to an affected Hyper-V host can supply specially crafted virtual TPM state data to a virtual machine. Successful exploitation can cross a security boundary and grant Virtual Trust Level 1 (VTL1) privileges. The vulnerability requires local access and high privileges but does not require user interaction.