Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
h30499.www3.hp.com
Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
1–10 of 17 posts
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#2Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#3"All we need to do is attach this usb stick and we can download all the files from their computer"
Well, almost, at least.
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#4I have no words...
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#5So Windows can run code simply by browsing to a directory with the default shell? I have no words...
While evidently their bug fix was a little hacky, I guess re-designing how Control Panel applet icons are rendered was considered too big of a change for what was essentially a security patch.
Hopefully they kill classic Control Panel completely at some stage in the next few years. Windows 8, 8.1, and now 10 are going down that road but there are a lot of legacy Control Panel applets by third parties which they have to deal with somehow.
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#6So Windows can run code simply by browsing to a directory with the default shell? I have no words...
Windows has a bug which was likely a design decision made in Windows 95 development (maybe earlier, Windows 3.1 had CPL applets also). Security wasn't taken as seriously in that era. While evidently their bug fix was a little hacky, I guess re-designing how Control Panel applet icons are rendered was considered too big of a change for what was essentially a security patch. Hopefully they kill classic Control Panel co…
They should rebuild it in something powershell can poke so every single windows setting can be done from the command line, slap a gui on top of that and manage it all with DSC. Much like how all the new server orientated features have gone.
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#7So Windows can run code simply by browsing to a directory with the default shell? I have no words...
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#8Out of curiosity, does anyone understand why it was a good idea in the first place to have icons pointing to a DLL instead of having a static icon name or icon id?
Re: Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix
#9So Windows can run code simply by browsing to a directory with the default shell? I have no words...
Windows has a bug which was likely a design decision made in Windows 95 development (maybe earlier, Windows 3.1 had CPL applets also). Security wasn't taken as seriously in that era. While evidently their bug fix was a little hacky, I guess re-designing how Control Panel applet icons are rendered was considered too big of a change for what was essentially a security patch. Hopefully they kill classic Control Panel co…