<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Asn1 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/asn1/</link><description>Recent content in Asn1 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 08:45:56 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/asn1/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-34180: Azure ASN.1 Heap Buffer Over-read</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-34180-azure-asn1-heap-buffer-over-read/</link><pubDate>Thu, 18 Jun 2026 08:45:56 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-34180-azure-asn1-heap-buffer-over-read/</guid><description>CVE-2026-34180 is a heap buffer over-read in ASN.1 parsing affecting Azure. Learn the security impact and remediation steps for cloud architects.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34180">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-34180 is a heap buffer over-read vulnerability in ASN.1 content parsing, affecting Microsoft Azure services. This type of flaw allows an attacker to read data beyond the intended memory boundary, potentially exposing sensitive information held in memory. While typically not directly exploitable for remote code execution, information disclosure vulnerabilities of this nature can aid further attacks by leaking cryptographic material or internal state.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your Azure deployments for any services or components that process ASN.1-encoded data (common in certificate and PKI workflows) and apply Microsoft&rsquo;s patch promptly. Assess whether any internet-facing services are affected, and consider monitoring for anomalous certificate-handling activity until the fix is confirmed in place.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34180">CVE-2026-34180 Heap Buffer Over-read in ASN.1 Content Parsing</a></p>
]]></content:encoded></item><item><title>CVE-2026-7383: Azure ASN.1 Heap Buffer Overflow</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-7383-azure-asn1-heap-buffer-overflow/</link><pubDate>Thu, 18 Jun 2026 08:42:51 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-7383-azure-asn1-heap-buffer-overflow/</guid><description>CVE-2026-7383 details a heap buffer overflow in ASN.1 multibyte string conversion affecting Azure. Learn the security impact and mitigation steps.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-7383">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-7383 is a possible heap buffer overflow vulnerability in ASN.1 multibyte string conversion, affecting Microsoft Azure services or components that rely on this cryptographic encoding standard. Heap buffer overflows can allow attackers to corrupt memory, potentially leading to remote code execution or denial of service. The impact depends on where the vulnerable component is deployed and whether it is reachable by untrusted input.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review any Azure services or workloads that process ASN.1-encoded data — such as certificate handling, PKI pipelines, or TLS termination points — and apply Microsoft&rsquo;s patches promptly. If a patch is not yet available, consider restricting exposure of affected endpoints and monitoring for anomalous certificate or encoding-related traffic.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-7383">CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion</a></p>
]]></content:encoded></item></channel></rss>