5 ms·
I agree that getting hacked through a browser is a far higher risk. However, the said browser is hopefully running with admin privileges, and if it is needed by
by ivegotnoaccount 4y ago
I agree that getting hacked through a browser is a far higher risk. However, the said browser is hopefully running with admin privileges, and if it is needed by the malware, it will need something else to exploit. If it was some small editor, it would serve no purpose for this. But we're talking about Riot Games, whose software is installed on hundreds of millions of machines and thus have a non-neglictible odd of being on the target's computer.
- prvit 4y agoAdmin privileges don’t matter, all the stuff you care about lives in your homedir. Have you ever seen a real world example of super common and super insecure AV drivers being exploited for LPE? Probably not, it’s not worth the trouble.
- ivegotnoaccount 4y agoI don't know if it has been exploited on the wild, but the subject seemingly interested some enough to find escalations bugs in https://en.m.wikipedia.org/wiki/SafeDisc https://en.m.wikipedia.org/wiki/SafeDisc.
- prvit 4y agoYes, there are tons of these bugs and tons of PoCs. However, in real life, nobody bothers to exploit them because there’s very little to gain by doing so.