GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Friday, 11-Apr-2025 21:29:32 JSTWill DormannWill Dormann
    • Kevin Beaumont
    • Busta

    @GossiTheDog @Busta
    Hilarious.
    The two things that MSRC seems to aim to to achieve are:

    1. Avoid saying anything about what their security updates do unless their hand is forced.
    2. Take the path of "least resistance" as opposed to fixing the root cause of problems. (In this case, non-admins can create subdirectories directly off of C:\)

    https://infosec.exchange/@wdormann/114319281111054638

    In conversationabout a month ago from infosec.exchangepermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      Will Dormann (@wdormann@infosec.exchange)
      from Will Dormann
      Attached: 2 images So, apparently this is the "fix" for [CVE-2025-21204](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204). Microsoft recently updated their advisory to say what the update does. Prior to everybody freaking out, the advisory for CVE-2025-21204 said nothing about what it does. Two gripes: 1. MSRC publishing content-free advisories has consequences, but they never seem to appreciate this. 2. I told MSRC **YEARS AGO** that they can avoid an entire class of LPE vulnerabilities in 3rd-party software **and** their own software by not allowing non-admin users to be able to create directories off of `C:\`. They refused to make any change because it might "break things". Great job, folks.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.