Windows Defenderの修正パッチによりディスク容量が枯渇する可能性

Microsoftが今週公開したWindows Defenderのゼロデイ脆弱性に対するセキュリティアップデートによって、攻撃者がコンピュータのハードドライブをデータで埋め尽くすことが可能になる恐れがある。この問題は、脆弱性を最初に報告した研究者によって指摘された。

Microsoftは水曜日、CVE-2026-50656として追跡されている脆弱性に対してパッチを公開した。このアップデートは、Defenderで使用されているMicrosoft Malware Protection Engineを対象としており、影響を受けるシステムに自動的にインストールされる。

研究者のNightmareEclipse氏は木曜日、追加された保護機能によってmpengine.dllファイルがデータを漏洩させる可能性があると報告した。これは、エンジンがSpyNetクラウドサービスを通じて特定のファイルを処理する際に、検疫コンテンツに対する通常のサイズ制限を回避することで発生する。

同研究者は、カスタムSMBサーバーを使用してこの挙動を誘発させる手法を説明した。悪意のあるファイルとサイズ超過のZone.Identifierストリームを組み合わせることで、Defenderがハングアップし、大量のディスク容量を占有してしまう可能性がある。

Microsoftはこの報告された副作用についてまだ確認していない。今回の開示は、今年初めから続いている同研究者とMicrosoftの間の論争を継続するものとなっている。

関連記事

A newly published zero-day exploit allows attackers with physical access to bypass BitLocker encryption on Windows 11 devices in seconds. The attack, named YellowKey, targets the default TPM-only configuration and grants full access to encrypted drives via a simple USB-based method.

AIによるレポート

Daemon Tools, a popular disk image mounting app, was compromised in a supply-chain attack starting April 8, delivering malware through official updates. Security firm Kaspersky reported infections on thousands of machines across over 100 countries. Users are urged to scan their systems immediately.

A ransomware group known as ShinyHunters exploited a critical zero-day flaw in Oracle’s PeopleSoft software to target about 100 organizations. The attackers stole gigabytes of data from victims, including the University of Nottingham, and issued extortion demands. Oracle has released a mitigation but not a full patch.

AIによるレポート

Google published proof-of-concept exploit code on Wednesday for a vulnerability in its Chromium browser that has gone unfixed for 29 months. The flaw affects Chrome, Microsoft Edge, and other Chromium-based browsers used by millions worldwide. It enables attackers to establish persistent connections for monitoring user activity and launching attacks.

このウェブサイトはCookieを使用します

サイトを改善するための分析にCookieを使用します。詳細については、プライバシーポリシーをお読みください。
拒否