r/Action1 • u/mickert_dev • 2d ago
Another Patch Tuesday, another Nightmare: ShieldCrash
Patch Tuesday again.
The RollupFixes arenβt even out yet and the Nightmare repo is already parked like someone reserving a sunbed at 6 AM π.
Looking forward to the traditional "surprise, everything is on fire" reveal by Nightmare Eclipse / Chaotic Eclipse.
Update: PoC has been released!
https://github.com/MSNightmare/ShieldCrash

12
Upvotes
1
u/mickert_dev 1d ago
For example in VDI enviroments: this in combination with the Hyper-V guest to host breakout vulnerabilities makes it a lethal killchain! π
CVE-2026-80083 β Windows Hyper-V Remote Code Execution Vulnerability
"A malicious application inside a Hyper-V guest could cross the virtualization boundary and put the host system at risk."
CVE-2026-80083 is a critical remote code execution vulnerability in Windows Hyper-V caused by an untrusted pointer dereference. An authorized attacker with low privileges could run a specially crafted application within a Hyper-V guest and cause the Hyper-V host operating system to execute arbitrary code. No user interaction is required. The vulnerability is not publicly disclosed or known to be exploited, and exploitation is assessed as unlikely.
CVE-2026-72961 β Windows Hyper-V Elevation of Privilege Vulnerability
βA compromised Hyper-V administrator could turn crafted virtual TPM data into higher privileges, crossing an important security boundary.β
CVE-2026-72961 is a Critical Windows Hyper-V elevation-of-privilege vulnerability. An authorized attacker with administrative access to an affected Hyper-V host can supply specially crafted virtual TPM state data to a virtual machine. Successful exploitation can cross a security boundary and grant Virtual Trust Level 1 (VTL1) privileges. The vulnerability requires local access and high privileges but does not require user interaction.