GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Tuesday, 16-Jun-2026 04:26:15 JSTWill DormannWill Dormann

    I just realized that I'm personally "credited" in April's Microsoft Patch Tuesday with a CVE-less "Defense-in-depth" update.

    The vulnerability?
    CAB files downloaded from the internet do not write the MotW for files extracted from them.

    I reported this to MSRC, and after refusing to generate a screen recording of the exploit (I mean, really?!), they finally acknowledged the problem. However, they went radio silent after that.

    Mark of the Web (MotW) evasions have gotten CVEs in the past. If we look in the last 2 years we have: CVE-2024-38213, CVE-2024-38217, CVE-2024-43487, CVE-2025-24061, CVE-2025-27472, CVE-2025-47160, CVE-2025-49740, CVE-2026-20824, CVE-2026-32225, CVE-2026-45595

    So, why does "Windows doesn't write MotW for extracted CAB file contents" get a CVE? Well, Microsoft is a CNA. So for the most part they can invent any rules that they'd like to play by. It could be as simple as "We're not particularly fond of you", and as a result, we have a vulnerability with no ID to track it.

    Here's a screen recording of a VM with March's Patch Tuesday level of updates. When you extract a file from a CAB file, no MotW is written. And as such, we get no protections that leverage the presence of MotW, such as SmartScreen, Smart Application Control, Office Protected View. In this case, we have a .URL file in a CAB. Double clicking on it results in a remote EXE running on your computer with no warning or other prompts. But, I suppose we all know that URL files are evil and have them blocked.

    In conversationabout 2 months ago from infosec.exchangepermalink

    Attachments


  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.