Intel Node

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

criticalvulnerability2026-06-09T21:21:00+00:00
vulnerabilitycveexploitationwindowscloud

Microsoft Patch Tuesday details for June 2026.

Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”.

  Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.

  Talos highlights 4 critical vulnerabilities as Microsoft has determined that their exploitation is “more likely:”  CVE-2026-42985  is a critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Remote Desktop Client which allows an unauthorized attacker to execute code over a network.   CVE-2026-47291  is a critical Remote Code Execution Vulnerability due to Integer overflow or wraparound in Windows HTTP Protocol Stack (http. sys).

 An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http. sys) to process packets.   CVE-2026-44803  and  CVE-2026-44812  are critical Remote Code Execution Vulnerability in the Windows Graphics component. This vulnerability is due to Integer overflow or wraparound in Windows Win32K – GRFX subsystem (graphics component). An unauthorized attacker, exploiting this vulnerability can execute malicious code locally.

  Talos highlights 23 critical vulnerabilities as Microsoft has determined that their exploitation is “less likely:”  CVE-2026-42992 ,  CVE-2026-44799 ,  CVE-2026-44801 ,  CVE-2026-47289  and  CVE-2026-48563  are critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Windows Remote Desktop Client allows an unauthorized attacker to execute code over a network.

 Successful exploitation of this vulnerability necessitates that an attacker takes additional steps to prepare the target environment before exploitation. In the case of a Remote Desktop connection, an attacker who controls a Remote Desktop Server could initiate a remote code execution (RCE) on the machine when a victim connects to the attacking server using the vulnerable Remote Desktop Client.

View Source