windows
Safeguard articles tagged "windows" — guides, analysis, and best practices for software supply chain and application security.
25 articles
The Windows CLFS Driver Produced a Second Confirmed-Exploited CVE, Two Years Apart
CVE-2023-36424 and CVE-2021-43226 both hit the same Windows Common Log File System Driver, one carrying a confirmed ransomware association, plus a separate Desktop Window Manager information leak.
Five More Microsoft CVEs Confirmed Exploited, Four on the Same Day
MSHTML, Windows Shell, Desktop Window Manager, and Office Word all produced confirmed-exploited bugs landing on CISA's KEV catalogue within a fifteen-day window in early 2026.
Nine Windows Privilege Escalation Bugs Confirmed Exploited — Why the Quiet Ones Matter Most
Nine local privilege-escalation and access-control vulnerabilities in Windows were confirmed exploited over the past year. None individually dramatic, together they define how far an intrusion spreads.
Eleven Microsoft CVEs From 2008 to 2013, All Confirmed Exploited This Past Year
A Windows buffer overflow from 2008, IE bugs from 2010, an Office flaw from 2009 — eleven old Microsoft vulnerabilities entered CISA's KEV catalogue, several on the exact same day.
Four Microsoft CVEs Describe a Complete Access-to-Domain-Control Chain
One unauthenticated RCE and three local privilege-escalation bugs across Windows and Active Directory Federation Services, confirmed exploited between July and September 2026.
Patch Tuesday August 2026: ~398 Flaws, 3 Zero-Days, and One the Norks Already Used
Microsoft shipped fixes for roughly 398 CVEs on 11 August. Three are zero-days, one is under active exploitation by Lazarus, and the vendor tallies disagree by nearly 30.
How to Download Maven for Windows and Verify It Safely
To download Maven for Windows, grab the binary zip from the official Apache site, verify its checksum, and set JAVA_HOME plus PATH. Here is the full, safe walkthrough.
PHP-CGI Argument Injection RCE on Windows (CVE-2024-4577) Explained
CVE-2024-4577 revived a decade-old PHP-CGI flaw through a Windows Unicode 'best-fit' quirk, yielding unauthenticated RCE. Here's the mechanism and the patched versions.
Semgrep Community Fall 2025: Native Windows and 3x Multicore
Semgrep's Fall 2025 Community Edition ships native Windows binaries, a memory-efficient multicore engine, and up to 3x scan speedups. We benchmarked it.
Follina (CVE-2022-30190) Explained: Code Execution From a Word Document With Macros Off
CVE-2022-30190, Follina, abused the Windows MSDT protocol handler so a Word document could run PowerShell — no macros, no enable-content click. Here is the ms-msdt mechanism.
PrintNightmare (CVE-2021-34527) Explained: When the Windows Print Spooler Ran Code as SYSTEM
CVE-2021-34527, PrintNightmare, let an authenticated attacker load a malicious printer driver through the Windows Print Spooler and execute code as SYSTEM — locally or across a domain.
CVE-2018-1271: Path traversal in Spring MVC static resour...
A path traversal flaw in Spring MVC's static resource handling let attackers on Windows deployments escape the web root and read arbitrary files.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.