The backbone of digital infrastructure: a close look at the servers powering today's technology.
Microsoft MDASH AI Scanner Finds Four Critical Windows RCEs
Microsoft’s innovative MDASH AI scanner has discovered four critical remote code execution (RCE) bugs within Windows. This significant finding highlights the advanced capabilities of the artificial intelligence system. The Microsoft MDASH AI scanner also secured the top position in the CyberGym public benchmark for AI agents. MDASH is an AI tool designed to find vulnerabilities across extensive codebases.
What Happened
The MDASH system uncovered four critical Windows RCEs. These severe bugs were found in key components of the operating system. Specific locations included the TCP/IP networking stack in the Windows kernel, along with the Internet Key Exchange (IKE) version 2 and Netlogon services. A vulnerability was also present in the domain name service (DNS) application programming interface (API) library.
Beyond these critical findings, MDASH identified an additional 12 vulnerabilities within the same stacks. This brings the total count to 16 CVEs. Microsoft issued patches for these vulnerabilities in April and May.
Details From Sources
Vulnerability Breakdown
Of the identified 16 vulnerabilities, 10 operate in kernel mode and six in user mode. Microsoft stated that the majority are reachable from a network position. They also clarified these do not require credentials for exploitation. This information was shared in a recent Microsoft security blog post. Source
Benchmark Performance
The MDASH system achieved a score of 88.45 percent in the CyberGym AI agents benchmark. This performance placed it in the top spot among competing AI systems. The benchmark consists of 1507 real-world vulnerability reproduction tasks. These tasks are drawn from 188 projects within Google’s OSS-Fuzz program. Source
Internal Testing
In a separate internal test, MDASH was evaluated using Microsoft’s non-released StorageDrive driver. The system successfully spotted all 21 deliberately injected vulnerabilities. It accomplished this with zero false positives. Microsoft did not publish the false positive rates for the 16 CVEs. The company also did not disclose the number of candidate findings generated before patching.
Why This Matters
An AI-driven system discovering critical RCEs holds significant importance. It underscores the potential of artificial intelligence to enhance software security. This innovation can proactively identify complex vulnerabilities. MDASH’s leading performance in an industry benchmark further validates its effectiveness. It demonstrates the power of autonomous vulnerability detection in modern cybersecurity.
Background Context
MDASH stands for multi-model agentic scanning harness. Microsoft describes MDASH as utilizing over 100 specialized AI agents. These agents operate “across an ensemble of frontier and distilled models.” Their purpose is to discover, debate, and prove exploitable bugs end-to-end. Microsoft’s Autonomous Code Security Team developed this advanced AI tool. Taesoo Kim, Microsoft’s vice president of agentic security, leads this team. Kim also leads Team Atlanta from Georgia Tech, which secured a US$20 million prize in DARPA’s AI Cyber Challenge competition. Kim is a professor at Georgia Tech, currently on leave with Microsoft.
Related Data or Statistics
- Number of critical RCE bugs found: 4
- Total vulnerabilities found in mentioned stacks: 16 (4 critical RCEs + 12 further vulnerabilities)
- Breakdown of vulnerabilities: 10 kernel mode, 6 user mode
- MDASH score in CyberGym benchmark: 88.45 percent
- CyberGym benchmark composition: 1507 real-world vulnerability reproduction tasks from 188 projects in Google’s OSS-Fuzz program
- Internal test results: 21 deliberately injected vulnerabilities detected with zero false positives
Future Implications (SPECULATIVE)
MDASH is currently in a private preview phase. It is available to a small number of customers and Microsoft’s security engineering teams. Other security teams can sign up to join the preview. This indicates potential wider availability and impact of the AI vulnerability scanning system.
Conclusion
Microsoft’s MDASH AI scanner marks a significant advancement in cybersecurity. It successfully identified critical Windows RCEs and demonstrated superior performance. The system topped the CyberGym benchmark. This achievement highlights the growing potential of AI models. Such models can greatly enhance code security and vulnerability detection efforts.
Frequently Asked Questions
- Q1: What is the Microsoft MDASH AI scanner?
- A1: The Microsoft MDASH AI scanner is an AI tool, also known as a multi-model agentic scanning harness. It was developed by Microsoft’s Autonomous Code Security Team. Its purpose is to find vulnerabilities in large codebases using over 100 specialized AI agents.
- Q2: What critical vulnerabilities did MDASH discover in Windows?
- A2: MDASH discovered four critical remote code execution (RCE) bugs in Windows. These were located in the TCP/IP networking stack, Internet Key Exchange (IKE) version 2, Netlogon services, and the DNS API library.
- Q3: How did MDASH perform in industry benchmarks?
- A3: MDASH achieved the top spot in the CyberGym AI agents benchmark with a score of 88.45 percent. It successfully tackled 1507 real-world vulnerability reproduction tasks.
- Q4: Who developed the MDASH system?
- A4: The MDASH system was developed by Microsoft’s Autonomous Code Security Team. This team is led by Taesoo Kim. Kim also leads Team Atlanta, a DARPA AI Cyber Challenge prize-winning group from Georgia Tech.
- Q5: Is the MDASH AI scanner widely available?
- A5: Currently, MDASH is in a private preview with a limited number of customers and Microsoft’s security engineering teams. However, other security teams can sign up to join the preview.
Interested security teams can sign up to join the private preview of the MDASH system. This offers an opportunity to explore its advanced AI vulnerability scanning capabilities firsthand.