Windows Notepad App Remote Code Execution Vulnerability
11–20 of 538 posts
Re: Windows Notepad App Remote Code Execution Vulnerability
#12Yeah, clicking unverified links in a markdown document to launch an executable.... Clicking unknown links is always a bad idea, but a CVE for that? I dunno....
Re: Windows Notepad App Remote Code Execution Vulnerability
#13From https://msrc.microsoft.com/update-guide/vulnerability/CVE-20... (there are many collapsible elements on this page, and they're also just for term definitions, sigh)
What a fucking terrible page for someone unfamiliar with the site. the "Learn More" links will allow you to learn what the terms "CWE", "CVSS", "Product Status" mean, but not to learn more about this vulnerability...
Anyway, it's not related to CoPilot, but because Notepad makes links clickable now...
Re: Windows Notepad App Remote Code Execution Vulnerability
#14For nearly thirty years, notepad.exe was the gold standard for a "dumb" utility which was a simple, win32-backed buffer for strings that did exactly one thing...display text. An 8.8 CVSS on a utility meant for viewing data is a fundamental failure of the principle of least privilege.
At some point, they need to stop asking "can we add this feature?" and start asking "does this text editor need a network-aware rendering stack?"
Re: Windows Notepad App Remote Code Execution Vulnerability
#15Yeah, clicking unverified links in a markdown document to launch an executable.... Clicking unknown links is always a bad idea, but a CVE for that? I dunno....
So yes, MS will likely denounce this as not their problem and move on.
Re: Windows Notepad App Remote Code Execution Vulnerability
#16So what this means is every Windows program is now a cve nightmare (or goldmine, depending on view)?
Re: Windows Notepad App Remote Code Execution Vulnerability
#17We have officially reached the logical conclusion of the feature-bloat-to-vulnerability pipeline. For nearly thirty years, notepad.exe was the gold standard for a "dumb" utility which was a simple, win32-backed buffer for strings that did exactly one thing...display text. An 8.8 CVSS on a utility meant for viewing data is a fundamental failure of the principle of least privilege. At some point, they need to stop aski…
I read the cwe not cve, was wrong. It's still early in the morning...
Re: Windows Notepad App Remote Code Execution Vulnerability
#18Yeah, clicking unverified links in a markdown document to launch an executable.... Clicking unknown links is always a bad idea, but a CVE for that? I dunno....
Re: Windows Notepad App Remote Code Execution Vulnerability
#19I miss when the Notepad was doing what the Notepad is supposed to do: show a text file, plain and simple.
Re: Windows Notepad App Remote Code Execution Vulnerability
#20I miss when the Notepad was doing what the Notepad is supposed to do: show a text file, plain and simple.
This was already better when the latest from MS was still called "* XP": https://liquidninja.com/metapad/