đ
Source : BleepingComputer â Date : 9 juin 2026
Microsoft a publiĂ© son Patch Tuesday de juin 2026, corrigeant 200 vulnĂ©rabilitĂ©s dont 6 zero-days sur lâensemble de son Ă©cosystĂšme logiciel. Ce bulletin massif couvre des dizaines de composants Windows, des produits cloud Azure, des applications Office, Exchange Server, Visual Studio Code et bien dâautres.
đŽ VulnĂ©rabilitĂ©s critiques notables CVE-2026-45648 â Windows Active Directory Domain Services Remote Code Execution (Critical) CVE-2026-45476 â Microsoft Azure Network Adapter (Linux MANA Driver) Elevation of Privilege (Critical) CVE-2026-33828 â Windows Device Health Attestation Elevation of Privilege (Critical) CVE-2026-32193 â Azure Kubernetes Service Remote Code Execution (Critical) CVE-2026-45463 / CVE-2026-45474 / CVE-2026-45472 / CVE-2026-45458 / CVE-2026-47635 / CVE-2026-45456 / CVE-2026-45461 â Microsoft Office Remote Code Execution multiples (Critical) CVE-2026-42985 / CVE-2026-47289 / CVE-2026-47654 / CVE-2026-42992 / CVE-2026-44801 / CVE-2026-44799 / CVE-2026-48563 â Remote Desktop Client Remote Code Execution multiples (Critical) CVE-2026-47288 â Windows Kerberos KDC Remote Code Execution (Critical) CVE-2026-47291 â HTTP.sys Remote Code Execution (Critical) CVE-2026-45641 / CVE-2026-47652 / CVE-2026-45607 â Windows Hyper-V Remote Code Execution (Critical) CVE-2026-44812 / CVE-2026-44803 â Windows Graphics Component Remote Code Execution (Critical) CVE-2026-44815 â DHCP Client Service Remote Code Execution (Critical) CVE-2026-42987 â Windows Deployment Services Remote Code Execution (Critical) CVE-2026-44810 â Microsoft Cryptographic Services Elevation of Privilege (Critical) CVE-2026-45657 â Windows Kernel Remote Code Execution (Critical) CVE-2026-48574 â Windows Media Remote Code Execution (Critical) CVE-2025-10263 â ARM kernel vulnerability (Critical) CVE-2026-26142 â Nuance PowerScribe Remote Code Execution (Critical) đ Composants les plus impactĂ©s Microsoft Office : ~15 CVE dont plusieurs RCE critiques (Outlook, Word, Excel, SharePoint) Remote Desktop Client : 11 CVE dont 7 critiques RCE Windows DWM Core Library : 11 CVE (EoP, Info Disclosure) Microsoft SharePoint : ~20 CVE (Spoofing, RCE) Windows Ancillary Function Driver for WinSock : 7 CVE EoP Windows Secure Boot : 8 CVE Security Feature Bypass Windows Push Notifications : 8 CVE (EoP, Info Disclosure) Azure Stack Edge : 2 CVE (RCE, Spoofing) Visual Studio Code : 6 CVE (EoP, Info Disclosure, Tampering, SFB) Exchange Server : 7 CVE (Spoofing, Info Disclosure, EoP, RCE) đ Types de vulnĂ©rabilitĂ©s Remote Code Execution (RCE) : majoritaire, nombreuses failles critiques Elevation of Privilege (EoP) : trĂšs rĂ©pandu sur les composants Windows Security Feature Bypass : BitLocker, Secure Boot, UEFI, MOTW Spoofing : Exchange, SharePoint, Bing, NTLM Information Disclosure : Office, RDP, Push Notifications Denial of Service : HTTP.sys, ASP.NET Core, Kerberos đ Type dâarticle : Patch de sĂ©curitĂ© â bulletin mensuel Microsoft. But principal : documenter lâensemble des correctifs publiĂ©s lors du Patch Tuesday de juin 2026 pour permettre aux Ă©quipes de sĂ©curitĂ© de prioriser les mises Ă jour.
...