<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Azure-Virtual-Desktop on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/azure-virtual-desktop/</link><description>Recent content in Azure-Virtual-Desktop on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 02:13:45 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/azure-virtual-desktop/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-11639: Chromium Use-After-Free in MS Edge</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-11639-chromium-use-after-free-compositing-microsoft-edge/</link><pubDate>Tue, 16 Jun 2026 02:13:45 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-11639-chromium-use-after-free-compositing-microsoft-edge/</guid><description>CVE-2026-11639 is a use-after-free flaw in Chromium Compositing affecting Microsoft Edge. Learn the security impact and patching advice for cloud environme</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11639">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability in the Chromium Compositing component has been assigned CVE-2026-11639 by Google Chrome. Microsoft Edge, being Chromium-based, inherits this flaw and has been patched via its regular Chromium ingestion process. Use-after-free bugs can allow attackers to execute arbitrary code by manipulating freed memory, making them particularly dangerous in browser contexts.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments — particularly relevant for Azure Virtual Desktop deployments. Validate that endpoint management policies (e.g. via Microsoft Intune) are enforcing automatic browser updates, and consider temporarily restricting Edge usage on high-risk systems until patching is confirmed.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11639">Chromium: CVE-2026-11639 Use after free in Compositing</a></p>
]]></content:encoded></item><item><title>CVE-2026-11630: Use-After-Free Flaw in Microsoft Edge</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-edge-chromium-use-after-free-cve-2026-11630/</link><pubDate>Tue, 16 Jun 2026 02:13:33 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-edge-chromium-use-after-free-cve-2026-11630/</guid><description>CVE-2026-11630 is a use-after-free vulnerability in Chromium&amp;#39;s File Input component affecting Microsoft Edge. Update Edge immediately to mitigate risk.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11630">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability (CVE-2026-11630) has been identified in the File Input component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Microsoft Edge users and enterprise deployments are affected until the Chromium-based patch is applied.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, including any Azure Virtual Desktop or Windows 365 deployments. Prioritise enforcement via Intune or Group Policy, and review browser auto-update policies to confirm they are active.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11630">Chromium: CVE-2026-11630 Use after free in File Input</a></p>
]]></content:encoded></item><item><title>CVE-2026-11628: Chromium Use-After-Free in Edge</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-11628-chromium-use-after-free-ozone-microsoft-edge/</link><pubDate>Tue, 16 Jun 2026 02:13:29 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-11628-chromium-use-after-free-ozone-microsoft-edge/</guid><description>CVE-2026-11628 is a use-after-free flaw in Chromium&amp;#39;s Ozone component affecting Microsoft Edge. Update Edge immediately to mitigate potential code executio</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11628">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability (CVE-2026-11628) has been identified in the Ozone display platform component of Chromium. Microsoft Edge, being Chromium-based, inherits this flaw and has been patched via Google&rsquo;s upstream Chromium release. Use-after-free bugs can allow attackers to execute arbitrary code by manipulating freed memory, making them potentially severe.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop deployments. Validate that your browser update policies enforce automatic patching and consider using Microsoft Endpoint Manager or Intune to confirm compliance.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11628">Chromium: CVE-2026-11628 Use after free in Ozone</a></p>
]]></content:encoded></item></channel></rss>