<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows-Lpe on CuraSec</title><link>https://curasec.metacog.co.kr/tags/windows-lpe/</link><description>Recent content in Windows-Lpe on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 12 Aug 2026 11:57:00 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/windows-lpe/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft August Patch Tuesday: 398 Fixes, Windows Driver LPE Zero-Day Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-patches-398-flaws-including-a-windows-driver-zero/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-patches-398-flaws-including-a-windows-driver-zero/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVE-2026-68820 is CISA KEV-listed with a public GitHub PoC and confirmed active exploitation — apply August 2026 Patch Tuesday updates immediately, prioritizing this kernel driver fix to close the SYSTEM-level LPE path.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active in-the-wild exploitation of a SYSTEM-level LPE means attackers may already have escalated on unpatched endpoints — hunt for anomalous SYSTEM-privilege process spawns from unexpected parent processes and tune EDR alerts for T1068 kernel-driver abuse since the public PoC widens attacker access.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A 398-patch batch with one actively exploited zero-day may strain standard patch SLAs — confirm your teams have triaged CVE-2026-68820 as this week&amp;rsquo;s priority and verify compliance with your critical-patch SLA before the next board or audit checkpoint.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-68820 — CISA KEV: listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>