Microsoft has introduced MDASH, an artificial intelligence system designed to identify security vulnerabilities in Windows before attackers can exploit them. The company announced the system on May 12, 2026, highlighting its ability to discover critical flaws during the testing phase. MDASH successfully located 16 security issues in Windows that were subsequently patched in the same month's Patch Tuesday release.
New tool finds security issues before hackers can exploit them
The system detected four critical remote code execution bugs, including CVE-2026-33827 and CVE-2026-33824. CVE-2026-33827 resides in tcpip.sys and is triggered by crafted IPv4 packets. CVE-2026-33824 is a pre-authentication double-free vulnerability in the IKEEXT service, which is reachable over UDP port 500. MDASH utilized over 100 specialized agents across frontier and distilled models to find these defects.
MDASH ranked at the top of the public CyberGym benchmark with a score of 88.45 percent. This performance outpaced Anthropic's Mythos Preview, which scored 83.1 percent, and OpenAI's GPT-5.5, which achieved 81.8 percent. In private testing against confirmed Microsoft Security Response Center cases in clfs.sys and tcpip.sys, the system achieved 100 percent recall for tcpip.sys and 96 percent recall for clfs.sys.
Microsoft currently offers MDASH in a limited private preview for a small group of enterprise customers. The company expects broader availability to follow in the months ahead. The system represents a shift toward automated vulnerability hunting, with Microsoft stating that MDASH proved its worth by finding flaws before any attacker could get to them.
Source: NotebookCheck




Discussion
0 comments