<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Elevation-of-Privilege on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/elevation-of-privilege/</link><description>Recent content in Elevation-of-Privilege on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 18 Jun 2026 14:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/elevation-of-privilege/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45480: Azure Active Directory Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/azure-active-directory-elevation-of-privilege-cve-2026-45480/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-active-directory-elevation-of-privilege-cve-2026-45480/</guid><description>CVE-2026-45480 is an Azure Active Directory elevation of privilege flaw allowing unauthenticated attackers to escalate privileges over a network. Patch urg</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45480">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in Azure Active Directory (CVE-2026-45480) allows an unauthenticated attacker to elevate their privileges over a network by exploiting improper authentication handling. This means an attacker without valid credentials could potentially gain elevated access to resources protected by Azure AD. Given how central Azure AD is to identity and access management across Microsoft cloud environments, the potential impact is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review Azure AD audit logs immediately for anomalous authentication events and ensure Conditional Access policies with strong MFA enforcement are in place; apply any Microsoft-issued patches or mitigations as a priority, and consider temporarily tightening network-level access to Azure AD endpoints where feasible.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45480">CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-32174: Azure Bot Service Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/azure-bot-service-elevation-of-privilege-cve-2026-32174/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-bot-service-elevation-of-privilege-cve-2026-32174/</guid><description>CVE-2026-32174 affects Azure Bot Service, allowing authenticated attackers to elevate privileges over a network. Learn the impact and remediation steps.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32174">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in Azure Bot Service allows an already-authenticated attacker to elevate their privileges over a network, potentially gaining access beyond their intended permission level. The flaw stems from improper authentication handling within the service. This is significant because bot services often have integrations with sensitive backend systems, meaning privilege escalation could have a wide downstream impact.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review service principals and managed identities associated with Azure Bot Service deployments and apply the principle of least privilege immediately. Monitor for any anomalous permission changes or unexpected API calls originating from bot service identities while awaiting or applying Microsoft&rsquo;s patch.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32174">CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-47645: M365 Copilot Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47645-microsoft-365-copilot-business-chat-privilege-escalation/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47645-microsoft-365-copilot-business-chat-privilege-escalation/</guid><description>CVE-2026-47645 is an open redirect vulnerability in Microsoft 365 Copilot Business Chat enabling privilege escalation over a network. Learn the risks and m</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47645">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in Microsoft 365 Copilot&rsquo;s Business Chat allows attackers to exploit an open redirect flaw, redirecting users to malicious sites without authentication. This can be leveraged to elevate privileges over a network, potentially enabling account takeover or credential theft. The risk is heightened given the widespread enterprise adoption of Microsoft 365 Copilot.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review and restrict access to Microsoft 365 Copilot&rsquo;s Business Chat where not business-critical, and ensure conditional access policies and phishing-resistant MFA are enforced. Monitor Microsoft&rsquo;s update guidance and apply any available patches or mitigations promptly, particularly in environments where Copilot has broad data access.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47645">CVE-2026-47645 Microsoft 365 Copilot&rsquo;s Business Chat Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-47647: Dynamics 365 Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47647-dynamics-365-elevation-of-privilege/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47647-dynamics-365-elevation-of-privilege/</guid><description>CVE-2026-47647 is a Dynamics 365 elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647">Microsoft Security Response Center</a></p>
<hr>
<p>A flaw in Microsoft Dynamics 365 allows an already-authenticated attacker to gain higher privileges than they should have, purely over the network — no physical access required. This means a low-privileged user or compromised account could be leveraged to access sensitive business data or administrative functions within Dynamics 365. Given how widely Dynamics 365 is used for CRM and ERP workflows, the potential business impact is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit current Dynamics 365 role assignments and apply the least-privilege principle immediately — remove any unnecessary elevated roles whilst Microsoft&rsquo;s patch is applied. Prioritise patching for tenants where Dynamics 365 is integrated with other Azure services or holds sensitive customer and financial data.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647">CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-48582: Exchange Online Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-exchange-online-elevation-of-privilege-cve-2026-48582/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-exchange-online-elevation-of-privilege-cve-2026-48582/</guid><description>CVE-2026-48582 is a Microsoft Exchange Online elevation of privilege flaw allowing authenticated attackers to gain higher permissions over a network.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48582">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in Microsoft Exchange Online allows an already-authenticated attacker to elevate their privileges beyond what they should have access to. Because Exchange Online is a widely used cloud email platform, a successful exploit could give an attacker significantly greater control over mailboxes, organisational data, or administrative functions. Microsoft has classified this as a network-exploitable issue, meaning no physical access is required.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review audit logs in Exchange Online for any anomalous privilege changes or unexpected admin role assignments, and ensure least-privilege principles are enforced across all Exchange Online accounts. Monitor the MSRC advisory for patch availability or mitigations and prioritise remediation given the broad blast radius of a compromised email platform.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48582">CVE-2026-48582 Microsoft Exchange Online Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-48584: Azure Synapse Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/azure-synapse-privilege-escalation-cve-2026-48584/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-synapse-privilege-escalation-cve-2026-48584/</guid><description>CVE-2026-48584 allows authenticated attackers to escalate privileges in Azure Synapse Analytics over a network. Learn the risk and remediation steps.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48584">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in Microsoft Azure Synapse Analytics allows an authenticated attacker to elevate their privileges over a network by exploiting unnecessarily broad execution permissions within the service. This means a user with standard access could potentially gain higher-level control than intended, putting sensitive data workloads and analytics environments at risk. The attack requires no physical access and can be carried out remotely, increasing its practical threat level.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review and restrict role assignments within Azure Synapse workspaces immediately, applying least-privilege principles to all identities — managed identities, service principals, and user accounts alike. Monitor Microsoft&rsquo;s patch guidance and apply any available fixes promptly; in the interim, audit network access controls to limit who can interact with Synapse endpoints.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48584">CVE-2026-48584 Microsoft Azure Synapse Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-35433: .NET Elevation of Privilege Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-35433-dotnet-elevation-of-privilege-vulnerability/</link><pubDate>Wed, 17 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-35433-dotnet-elevation-of-privilege-vulnerability/</guid><description>Microsoft updates CVE-2026-35433, a .NET Elevation of Privilege vulnerability, removing Windows 11 21H1 and 22H2 from the affected platforms list.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-35433 is an Elevation of Privilege vulnerability in .NET that allows an attacker to gain higher system permissions than intended. Microsoft has revised the advisory to clarify that Windows 11 versions 21H1 and 22H2 are no longer considered affected. Organisations running .NET on other impacted platforms should review their patch status promptly.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your Azure-hosted workloads and CI/CD pipelines running .NET to confirm which runtime versions are deployed, and verify patched versions are in use. Remove Windows 11 21H1 and 22H2 from your affected-systems tracking if previously included.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35433">CVE-2026-35433 .NET Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-42828 Windows ProjFS Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-42828-windows-projected-file-system-elevation-of-privilege/</link><pubDate>Wed, 17 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-42828-windows-projected-file-system-elevation-of-privilege/</guid><description>CVE-2026-42828 is a Windows Projected File System elevation of privilege flaw. Learn what it means for Azure and hybrid Windows environments.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-42828 is an elevation of privilege vulnerability in the Windows Projected File System (ProjFS), a component that allows applications to present virtual file system content. If exploited, an attacker could gain elevated privileges on an affected Windows system. This update is an acknowledgement addition only and contains no new technical or patch information.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> No immediate action is required as this is a non-technical acknowledgement update with no change to patch status or severity. Ensure Windows systems in your Azure or hybrid environments have already applied the relevant cumulative updates addressing this CVE, and verify coverage through your patch management tooling.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828">CVE-2026-42828 Windows Projected File System Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-40371: Dynamics 365 On-Prem EoP Fix</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-40371-microsoft-dynamics-365-on-premises-elevation-of-privilege/</link><pubDate>Tue, 16 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-40371-microsoft-dynamics-365-on-premises-elevation-of-privilege/</guid><description>Microsoft corrects patch guidance for CVE-2026-40371, a Dynamics 365 on-premises privilege escalation flaw. The real fix is in v9.1 Update 1.45.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371">Microsoft Security Response Center</a></p>
<hr>
<p>A privilege escalation vulnerability in Microsoft Dynamics 365 on-premises has been assigned CVE-2026-40371, allowing an attacker to gain elevated permissions within the application. Microsoft has corrected its remediation guidance: the fix is contained in Dynamics 365 Server v9.1 Update 1.45 (build 9.1.0045.0011), not the previously stated version 6.2. Organisations that applied the earlier guidance should verify they are running the correct build to ensure they are actually protected.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your Dynamics 365 on-premises deployments immediately and confirm the installed build is 9.1.0045.0011 or later — do not assume earlier patching attempts were sufficient given the corrected version guidance. If you manage hybrid environments where on-premises Dynamics 365 integrates with Azure services, treat unpatched instances as a potential lateral movement risk and prioritise the update accordingly.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371">CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-50656: Microsoft Defender EoP Vulnerability</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-defender-elevation-of-privilege-cve-2026-50656-rogueplanet/</link><pubDate>Tue, 16 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-defender-elevation-of-privilege-cve-2026-50656-rogueplanet/</guid><description>CVE-2026-50656 &amp;#39;RoguePlanet&amp;#39; is an unpatched elevation of privilege flaw in the Microsoft Malware Protection Engine. Learn the risks and mitigations.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656">Microsoft Security Response Center</a></p>
<hr>
<p>A publicly disclosed elevation of privilege vulnerability, tracked as CVE-2026-50656 and nicknamed &lsquo;RoguePlanet&rsquo;, has been found in the Microsoft Malware Protection Engine within Microsoft Defender. An attacker exploiting this flaw could gain elevated system privileges on affected machines. Microsoft has acknowledged the issue but has not yet released a patch, meaning systems remain exposed whilst a fix is in development.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> With no patch currently available, prioritise compensating controls: ensure Defender is configured with least-privilege service accounts, monitor for anomalous privilege escalation events via Microsoft Sentinel or your SIEM, and consider temporarily increasing alert sensitivity on endpoints running Microsoft Defender until the update is released.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656">CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item></channel></rss>