Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

On Tuesday, Microsoft unveiled a patch for a significant zero-day vulnerability that had been exposed by a researcher embroiled in a contentious relationship with the tech giant. Alongside this, another zero-day vulnerability also appears to have been rectified. Known by the alias Nightmare Eclipse, the researcher has recently disclosed several serious vulnerabilities, raising concerns about potential exploitation in real-world scenarios. This series of disclosures, which included proof-of-concept code, followed what Nightmare Eclipse described as Microsoft's failure to adhere to a prior agreement concerning the vulnerabilities that were under discussion. In a statement from March, the researcher expressed dissatisfaction, stating, "But someone violated our agreement and left me homeless with nothing. They knew this would happen, and they still stabbed me in the back anyway; this is their decision, not mine." As part of its June patch release, Microsoft addressed CVE-2026-45586, a vulnerability that Nightmare Eclipse had disclosed in May under the name GreenPlasma. This particular vulnerability allows for local privilege escalation, enabling low-level privileges on a device to bypass operating system protections and gain full SYSTEM rights, which are necessary for installing malware. Microsoft characterized CVE-2026-45586 as having low complexity for exploitation and requiring no user interaction, indicating a significant risk of active exploitation in the wild. The issue stemmed from "improper link resolution before file access ('link following') in the Windows Collaborative Translation Framework." Thankfully, there have been no confirmed instances of this vulnerability being actively exploited thus far. Additionally, vulnerability analyst Will Dormann from Tharros Labs noted that Tuesday’s patch also addressed a separate vulnerability disclosed by Nightmare Eclipse, referred to as MiniPlasma. Interestingly, he pointed out that Microsoft did not mention this specific fix. This vulnerability was allegedly resolved six years ago under the identifier CVE-2020-17103, but it seems either the fix was inadequate or the issue resurfaced as a regression.

Sources : Ars Technica

Published On : Jun 09, 2026, 21:00

Science
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe

Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...

Business Today | Jul 25, 2026, 01:00
Vision Breakthrough: US Startup Launches Groundbreaking Retina Chip in Europe
Startups
Warner Bros. Takes Legal Action Against Amazon Over Executive Poaching Allegations

Warner Bros. Discovery has initiated legal proceedings against Amazon, accusing the tech giant of unlawful interference ...

TechCrunch | Jul 25, 2026, 21:25
Warner Bros. Takes Legal Action Against Amazon Over Executive Poaching Allegations
Cybersecurity
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants

In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...

TechCrunch | Jul 25, 2026, 21:00
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants
Gadgets
OpenAI's Micro Keypad: A Novelty for Coders or Just a Confounding Gadget?

Last week, OpenAI made its debut in the hardware landscape with the launch of Micro, a stylish keypad designed to integr...

TechCrunch | Jul 25, 2026, 24:40
OpenAI's Micro Keypad: A Novelty for Coders or Just a Confounding Gadget?
AI
Nvidia Strikes Major Deal with SK Hynix to Secure AI Memory Supply

Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...

CNBC | Jul 25, 2026, 05:15
Nvidia Strikes Major Deal with SK Hynix to Secure AI Memory Supply
View All News