Live data from Hacker News

Windows 10 RCE: The exploit is in the link

positive.security

21–30 of 58 posts

Re: Windows 10 RCE: The exploit is in the link

#21

People with technical knowledge who prefer to use Windows should have their brains examined.

At work, I am stuck with windows.

At home, I want to game and I want to use photoshop.

Both kinda leave me stuck with windows. I could go windows at work and mac at home. But that would require me learning mac, trying to game on mac, replacing a self-build PC with either an M1 chip in a mac-mini / imac. Or with an actual laptop when I only really need a desktop.

All whilst I really like linux. I am stuck using either Windows or Windows and Mac.

Re: Windows 10 RCE: The exploit is in the link

#22
post #3

"Microsoft Bug Bounty Program's (MSRC) response was poor: Initially, they misjudged and dismissed the issue entirely. After our appeal, the issue was classified as "Critical, RCE", but only 10% of the bounty advertised for its classification was awarded ($5k vs $50k). The patch they came up with after 5 months failed to properly address the underlying argument injection (which is currently also still present on Windo…

And apparently Win11 too. Don't all protocol handlers invoke some execution? Like http goes to my browser (only Edge) and that other windows internal one which also goes to Edge (and resets my registered http handler)

> Don't all protocol handlers invoke some execution?

Sure, but you don't expect arbitrary code execution. The important distinction is whether the attacker can control what is executed. So if you click on a HTTPS link, you should be safe to assume that it opens a new browser tab, and not open a command prompt like in that example.

Re: Windows 10 RCE: The exploit is in the link

#23
post #18

Am I understanding this correctly that this exploit uses edge OR simply having teams installed (which is default in windows)? Are there any community patches for this since microsoft has failed to patch what appears to be a 0 day (especially for windows 10)?

>having teams installed (which is default in windows) Teams is not default in Windows (at least my install) - I don't have it and when I have to do meetings in Teams and I am on my Windows machine I just open the meeting in Chrome.

Teams was installed without my approval on my private unmanaged laptop running Windows 10 Professional.

If you don't have Teams yet, you are either in another rollout, you have done something to prevent it or your PC is managed by someone who have prevented it somehow. I think that covers all.

As for why I only use Windows now and then and since I have had a habit of supporting others I keep my personal Windows PCs as plain as possible so I can see what others suffer (obviously I remove nagware like McAfee and make sure spyware like Chrome isn't set as default browser but I have gone as far as to voluntarily run my PC with Norwegian language).

Re: Windows 10 RCE: The exploit is in the link

#25
post #16

"Microsoft Bug Bounty Program's (MSRC) response was poor: Initially, they misjudged and dismissed the issue entirely." I recently ran into a similar issue with MSRC. I reported two exactly similar(near perfect) heap overflows exploitable from a local perspective with some time in between. The first report was awarded the maximum payout, and patched as 'Important'. Meanwhile, MSRC changed its rules related local explo…

If you're not selling the exploits to Microsoft, where else do you sell them?

Re: Windows 10 RCE: The exploit is in the link

#26
post #23
post #18

Earlier quoted context omitted.

>having teams installed (which is default in windows) Teams is not default in Windows (at least my install) - I don't have it and when I have to do meetings in Teams and I am on my Windows machine I just open the meeting in Chrome.

Teams was installed without my approval on my private unmanaged laptop running Windows 10 Professional. If you don't have Teams yet, you are either in another rollout, you have done something to prevent it or your PC is managed by someone who have prevented it somehow. I think that covers all. As for why I only use Windows now and then and since I have had a habit of supporting others I keep my personal Windows PCs a…

I'm curious as to the effects of running with a Norwegian language with security. Any chance at enlightenment?

Re: Windows 10 RCE: The exploit is in the link

#28
post #16

"Microsoft Bug Bounty Program's (MSRC) response was poor: Initially, they misjudged and dismissed the issue entirely." I recently ran into a similar issue with MSRC. I reported two exactly similar(near perfect) heap overflows exploitable from a local perspective with some time in between. The first report was awarded the maximum payout, and patched as 'Important'. Meanwhile, MSRC changed its rules related local explo…

If you're not selling the exploits to Microsoft, where else do you sell them?

https://zerodium.com/, the going rate for a full exploit there (and I assume, one that works quickly & leaves little trace, i.e. a high quality exploit, never dealt with them before) is 80k.

Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.

Re: Windows 10 RCE: The exploit is in the link

#29

People with technical knowledge who prefer to use Windows should have their brains examined.

It's me, I have technical knowledge and prefer to use Windows. I've shipped production apps that are used by millions of people every day (including probably you) on every desktop operating system. Ask Me Anything about my Brain

Re: Windows 10 RCE: The exploit is in the link

#30

"Microsoft Bug Bounty Program's (MSRC) response was poor: Initially, they misjudged and dismissed the issue entirely. After our appeal, the issue was classified as "Critical, RCE", but only 10% of the bounty advertised for its classification was awarded ($5k vs $50k). The patch they came up with after 5 months failed to properly address the underlying argument injection (which is currently also still present on Windo…

Microsoft is teaching bounty seekers to look elsewhere and honestly that is a very stupid decision for such a deep pocketed company. It is only making their software less safe.
Post reply on HN