One thing I haven't seen stated explicitly about #CVE_2024_3094: The engineer who found this is a Microsoft employee. Does that mean Microsoft runs the vulnerable configuration? Given that it isn't that common, could we reasonably deduce that Microsoft was a target?
Conversation
Notices
-
Embed this notice
Taggart :donor: (mttaggart@infosec.town)'s status on Wednesday, 03-Apr-2024 01:56:22 JST Taggart :donor: -
Embed this notice
Taggart :donor: (mttaggart@infosec.town)'s status on Wednesday, 03-Apr-2024 02:16:55 JST Taggart :donor: @GossiTheDog Perhaps I misunderstood, but it seemed like not every Linux system would be using the patched version of sshd that would lead to RCE?
-
Embed this notice