What Is Microsoft MDASH?
MDASH is a multi-model agentic scanning harness built by Microsoft’s Autonomous Code Security team. Unlike single-model approaches, it uses an ensemble of frontier and distilled AI models working together. These agents discover, debate, and prove exploitable bugs end-to-end, mimicking how a team of human security researchers would operate — but at machine speed.
How Well Did MDASH Perform?
The results were striking:
- 21 of 21 planted vulnerabilities found with zero false positives on a private test driver
- 96% recall against five years of confirmed MSRC cases in clfs.sys
- 100% recall in tcpip.sys
- 88.45% on the CyberGym benchmark of 1,507 real-world vulnerabilities — roughly 5 points ahead of the next entry
What Vulnerabilities Did It Find?
This month’s Patch Tuesday includes 16 CVEs found by MDASH, including:
- Critical remote code execution flaws in the Windows kernel TCP/IP stack
- Vulnerabilities in the IKEv2 service
- Unauthenticated remote code execution in DNS and Netlogon components