<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Tampering on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/tampering/</link><description>Recent content in Tampering on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 14:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/tampering/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-42895: Microsoft Copilot Command Injection Flaw</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-copilot-command-injection-tampering-cve-2026-42895/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-copilot-command-injection-tampering-cve-2026-42895/</guid><description>CVE-2026-42895 is a command injection vulnerability in Microsoft Copilot allowing unauthenticated network attackers to tamper with the service. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42895">Microsoft Security Response Center</a></p>
<hr>
<p>A command injection vulnerability in Microsoft Copilot allows an unauthenticated attacker to tamper with the service over a network, without requiring any user interaction or elevated privileges. The flaw stems from improper handling of special characters within commands, a class of vulnerability that can enable attackers to manipulate application behaviour or underlying systems. Given Copilot&rsquo;s integration across Microsoft 365 and Azure services, the potential blast radius for affected organisations is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your organisation&rsquo;s exposure to Microsoft Copilot endpoints and ensure network-level controls restrict access to trusted users only; monitor Microsoft&rsquo;s remediation guidance closely and apply any available patches or mitigations immediately, particularly if Copilot is integrated with sensitive data sources or enterprise workflows.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42895">CVE-2026-42895 Microsoft Copilot Tampering Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-45602 Windows DHCP Tampering Vulnerability</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-45602-windows-dhcp-tampering-vulnerability/</link><pubDate>Tue, 16 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-45602-windows-dhcp-tampering-vulnerability/</guid><description>CVE-2026-45602 covers a Windows DHCP tampering vulnerability. Latest update is a CWE correction only — no patch or severity changes required.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-45602 is a tampering vulnerability affecting the Windows Dynamic Host Configuration Protocol (DHCP) service. This update is an informational change only, correcting the CWE classification with no change to severity, patch status, or exploitability. No new action is required as a result of this revision.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> No immediate action is required from this update — verify that any existing mitigations or patches applied for CVE-2026-45602 remain in place, and update internal vulnerability tracking records to reflect the revised CWE classification.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602">CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability</a></p>
]]></content:encoded></item></channel></rss>