<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Pki on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/pki/</link><description>Recent content in Pki on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 08:45:04 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/pki/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-42767: Azure CRMF NULL Pointer Dereference</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-42767-azure-crmf-encrypted-value-null-pointer-dereference/</link><pubDate>Thu, 18 Jun 2026 08:45:04 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-42767-azure-crmf-encrypted-value-null-pointer-dereference/</guid><description>CVE-2026-42767 is a NULL pointer dereference in CRMF EncryptedValue decryption affecting Azure. Learn the security impact and recommended mitigations.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42767">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-42767 is a NULL pointer dereference vulnerability in the CRMF (Certificate Request Message Format) EncryptedValue decryption process, affecting an Azure-related component. This class of vulnerability can cause application crashes or potentially be leveraged to execute arbitrary code, depending on how the affected component handles malformed input. If exploited, it could disrupt certificate management operations or be used as part of a broader attack chain targeting cryptographic infrastructure.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review whether any Azure services or workloads in your environment rely on CRMF-based certificate issuance or decryption workflows, and apply any available Microsoft patches immediately. Until patched, consider restricting access to certificate management endpoints and monitoring for anomalous certificate request activity.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42767">CVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue Decryption</a></p>
]]></content:encoded></item><item><title>CVE-2026-34182: Azure CMS AuthEnvelopedData Forgery Flaw</title><link>https://zxcloudsecurity.co.uk/posts/azure-cms-authenvelopeddata-forged-messages-cve-2026-34182/</link><pubDate>Tue, 16 Jun 2026 09:14:59 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-cms-authenvelopeddata-forged-messages-cve-2026-34182/</guid><description>CVE-2026-34182 allows forged CMS AuthEnvelopedData messages to be accepted as valid, threatening message integrity in Azure environments. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34182">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-34182 is a vulnerability in CMS (Cryptographic Message Syntax) AuthEnvelopedData processing that may allow an attacker to submit forged encrypted messages that are incorrectly accepted as valid. This undermines the integrity guarantees of authenticated encryption, potentially enabling an attacker to bypass message authentication checks. The flaw is particularly concerning in any Azure service or component that relies on CMS for secure message handling.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review any Azure workloads or integrations that consume CMS AuthEnvelopedData — such as certificate-based messaging, encrypted payloads, or PKI workflows — and apply Microsoft&rsquo;s patch promptly. Until patched, consider adding upstream validation controls or signature verification layers to reduce exposure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34182">CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages</a></p>
]]></content:encoded></item><item><title>CVE-2026-42766: NULL Dereference in CMS Decryption</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-42766-null-dereference-cms-decryption-azure/</link><pubDate>Thu, 18 Jun 2026 08:44:21 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-42766-null-dereference-cms-decryption-azure/</guid><description>CVE-2026-42766 is a NULL dereference flaw in password-based CMS decryption that could allow denial of service via malformed encrypted input on Azure.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42766">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-42766 is a potential NULL dereference vulnerability affecting password-based CMS (Cryptographic Message Syntax) decryption, disclosed via Microsoft&rsquo;s Security Response Centre. A NULL dereference flaw can cause an application or service to crash when processing malformed or malicious encrypted data, potentially leading to denial of service. This matters because CMS is widely used in certificate handling, S/MIME email, and PKI workflows, meaning affected services could be disrupted by a crafted payload.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review whether any Azure services or workloads in your environment rely on password-based CMS decryption, and apply Microsoft&rsquo;s patch or mitigations promptly — prioritise internet-facing or shared services where an attacker could supply crafted encrypted input to trigger a crash.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42766">CVE-2026-42766 Possible NULL Dereference in Password-Based CMS Decryption</a></p>
]]></content:encoded></item></channel></rss>