Researcher sharpens criticism of Microsoft's handling of RedSun
The researcher known as ChaoticEclipse has published new statements about the Windows vulnerabilities RedSun and YellowKey. The claim is that Microsoft patched RedSun without assigning a CVE or issuing an advisory, despite the flaw reportedly being under active exploitation. On YellowKey, the researcher argues the root cause is still not correctly identified, that TPM with PIN does not prevent exploitation, and that further material is being withheld. The technical details have not been published, and the claims remain unconfirmed by others.
What this means for your organisation
The case matters less for its technical detail than for what it illustrates: you cannot base vulnerability management solely on the vendor's CVE count. A silently fixed flaw never appears in your scanner. At the same time, these are single-source, unverified claims, and there is no reason to overhaul your client platform on the strength of a blog post. The sensible response is to watch, not to react.
Berigo recommends
- Keep Windows clients current on updates regardless, including fixes not tied to a CVE number.
- Treat disk encryption with TPM and PIN as one layer among several, not as final protection of data on the device.
- Establish a standing routine for who assesses unconfirmed vulnerability claims, so each one does not turn into an ad hoc debate.
- Hold off on measures beyond normal patching until there is technical evidence that can be verified.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch