Security & Threat Intelligence · 24.08.2026, 21:46 UTC
ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability
| Schweregrad | low |
|---|---|
| CVSS | 3.3 |
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Zero Day Initiative ↗ |
| Veröffentlicht | 24.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad niedrig (CVSS 3.3). Betroffene Kennungen: CVE-2026-50508. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- high ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability
- info Amazon Aurora now supports PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23
- info Amazon RDS for MySQL now supports new minor version 8.4.11
- info OpenAI GPT-5.6 Terra and Luna now available on Amazon Bedrock in AWS GovCloud (US)