{"id":483352,"date":"2026-05-13T23:12:16","date_gmt":"2026-05-13T23:12:16","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/483352\/"},"modified":"2026-05-13T23:12:16","modified_gmt":"2026-05-13T23:12:16","slug":"microsofts-agentic-security-system-mdash-uncovers-four-critical-windows-rce-flaws","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/483352\/","title":{"rendered":"Microsoft&#8217;s agentic security system MDASH uncovers four critical Windows RCE flaws"},"content":{"rendered":"<p>Microsoft Corp. today detailed a new artificial intelligence-powered vulnerability discovery system that uncovered 16 previously unknown flaws in Windows networking and authentication components, including four critical remote code execution bugs patched in this month\u2019s Patch Tuesday release.<\/p>\n<p>The system, codenamed MDASH for multi-model agentic scanning harness, was built by Microsoft\u2019s Autonomous Code Security team in collaboration with the company\u2019s Windows Attack Research and Protection group. MDASH orchestrates more than 100 specialized AI agents across an ensemble of frontier and distilled models to find, debate and prove exploitable bugs from end to end.<\/p>\n<p>The 16 vulnerabilities span the Windows TCP\/IP stack, the IKEEXT IPsec service, HTTP.sys, Netlogon, DNS resolution and the Telnet client.<\/p>\n<p>Ten of the vulnerabilities were kernel-mode and six were usermode and most were reachable from a network position without credentials.<\/p>\n<p>Among the four rated critical are CVE-2026-33827, a remote unauthenticated use-after-free in tcpip.sys triggered by crafted IPv4 packets carrying the Strict Source and Record Route option and CVE-2026-33824, a double-free in the IKEv2 service reachable over UDP port 500 that yields code execution as LocalSystem.<\/p>\n<p>The vulnerabilities were also not the kind a single-pass scanner would typically surface. The tcpip.sys flaw involved a reference-counted Path object whose ownership was dropped before a later reuse, with three independent concurrent free paths in play. The IKEEXT double-free vulnerability spanned six source files and was only visible when contrasted against a correctly handled site elsewhere in the same code base.<\/p>\n<p>Microsoft also disclosed benchmark results to back claims that the harness is performing at production scale.<\/p>\n<p>On a private test driver called StorageDrive containing 21 planted vulnerabilities, MDASH identified all 21 with zero false positives. Against five years of confirmed Microsoft Security Response Center cases, the system recorded 96% recall on clfs.sys and 100% on tcpip.sys. On the public CyberGym benchmark, which covers 1,507 real-world vulnerability reproduction tasks drawn from 188 open-source projects, MDASH scored 88.45%, the top result on the leaderboard and roughly five points ahead of the next entry.<\/p>\n<p>The architecture runs the work as a pipeline of prepare, scan, validate, dedup and prove stages, with specialized agent roles at each step. State-of-the-art models handle heavy reasoning, distilled models act as cost-effective debaters for high-volume passes and a separate frontier model provides an independent counterpoint. Domain plugins inject context the foundation models cannot infer on their own, including kernel calling conventions, lock in variants and interprocess communication trust boundaries.<\/p>\n<p>Taesoo Kim, vice president of agentic security at Microsoft, wrote in the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/12\/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark\/\" rel=\"nofollow noopener\" target=\"_blank\">company\u2019s announcement<\/a> that the durable advantage in AI-driven vulnerability discovery lies in the agentic system around the model rather than any single model. Several members of the Autonomous Code Security team came from Team Atlanta, the group that won first place in the $20 million DARPA AI Cyber Challenge by building an autonomous cyber-reasoning system that found and patched real bugs in open-source projects.<\/p>\n<p>MDASH is already being used internally by Microsoft engineering teams and is being tested by a limited set of customers as part of a private preview.<\/p>\n<p>Image: Microsoft<\/p>\n<p>Support our mission to keep content open and free by engaging with theCUBE community. <strong>Join theCUBE\u2019s Alumni Trust Network<\/strong>, where technology leaders connect, share intelligence and create opportunities.<\/p>\n<ul>\n<li class=\"text-xl md:text-2xl text-gray-300 mb-8 max-w-4xl mx-auto\" data-replit-metadata=\"client\/src\/pages\/Home.tsx:123:12\" data-component-name=\"p\"><strong>15M+ viewers of theCUBE videos<\/strong>, powering conversations across AI, cloud, cybersecurity and more<\/li>\n<li data-replit-metadata=\"client\/src\/pages\/Home.tsx:123:12\" data-component-name=\"p\"><strong>11.4k+ theCUBE alumni<\/strong> \u2014 Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.<\/li>\n<\/ul>\n<p><strong>About SiliconANGLE Media<\/strong><\/p>\n<p>SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fsiliconangle.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=SiliconANGLE&amp;index=9&amp;md5=646b1b564e2259100a2b8638aab0a552\" rel=\"nofollow noopener\" target=\"_blank\">SiliconANGLE<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecube.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Network&amp;index=10&amp;md5=7de2a85f95ab4a4a495cede20b8cb1da\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Network<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fthecuberesearch.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Research&amp;index=11&amp;md5=7bb33676722925eb57d588ec343e4f6f\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Research<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.cube365.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=CUBE365&amp;index=12&amp;md5=d310fb35919714e66ad8d42c9c0c1bc6\" rel=\"nofollow noopener\" target=\"_blank\">CUBE365<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecubeai.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+AI&amp;index=13&amp;md5=b8b98472f8071b23ebb10ab9a8dd0683\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE AI<\/a> and theCUBE SuperStudios \u2014 with flagship locations in Silicon Valley and the New York Stock Exchange \u2014 SiliconANGLE Media operates at the intersection of media, technology and AI.<\/p>\n<p>Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft Corp. today detailed a new artificial intelligence-powered vulnerability discovery system that uncovered 16 previously unknown flaws in&hellip;\n","protected":false},"author":2,"featured_media":483353,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[74],"tags":[2081,18,19,17,211387,2082,82],"class_list":{"0":"post-483352","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-duncan-riley","9":"tag-eire","10":"tag-ie","11":"tag-ireland","12":"tag-microsofts-agentic-security-system-mdash-uncovers-four-critical-windows-rce-flaws","13":"tag-siliconangle","14":"tag-technology"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116569804110366301","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/483352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=483352"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/483352\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/483353"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=483352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=483352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=483352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}