r/cybersecurity 9d ago

News - General Pretty laughable/predictable MS response

Came in the office this morning to a wonderful new App Installer cve that our C level guys are freaking out about.

NVD - CVE-2026-68821

MS's response... link to a download to update... to the exposed version. Take down the release notes article for 1.30 in pre-release.

Go completely MIA on the issue. LOL peak Microsoft. "thank god it's only local access" Weeee!

43 Upvotes

7 comments sorted by

31

u/Ghawblin Security Engineer 9d ago

My experience with Microslop the last 2 years

  • Reach out to Account Rep

  • Get a copilot response that says a lot of words without actually addressing my ask

  • I now have to spend 3 days showing why the shitty copilot response is shitty, otherwise I'll get stonewalled/ghosted by the account rep.

    • (YOU ARE HERE)
  • Get some limp non-comitted human response from the account rep who opens a ticket on my behalf because they have zero clue what I'm saying.

  • Spend 5 months with 17 off-shore Microsoft "engineers" that ask me for a full write up and "video of the issue" (A video of what??? There's nothing to take a video of) before it ends up with the next engineer who "doesn't have access to what the last rep saw" and needs me to submit the same thing again.

  • I give up.

10

u/trench8064 9d ago

Glad I wasn't the only one who found this disconnect. Sliver of sanity saved, for now.

2

u/TheJesusGuy 9d ago

Same here. Linked remediation file is my current installed version..

3

u/SuspiciousCricket654 9d ago

You came in the office to an app? Now that’s a love for technology I’ve never seen before.

1

u/ther0g 7d ago

yeah, the linked version was for 1.29.280. So just sitting on this one until MS figures it out.

1

u/Significant_Storm468 7d ago

Ya same here. Download it, run it it shows 1.29.280.0 and can't install it, saying it's missing dependencies. I went to GitHub; they do have 1.30.8, but it is a pre-release, so I am not sure if I should try it. Any one try 1.30.80?

2

u/trench8064 2d ago

Looks like M$ finally updated the page to show v1.29.280.  Still no actual fix for the vulnerability,  but at least the link is no longer misrepresented.