15 ms·
“Zero-Click RCE” This appears to require attacker controlled data already being written to a settings XML file in specific locations on disk. Put simply, this
by jerrythegerbil 3mo ago
“Zero-Click RCE”
This appears to require attacker controlled data already being written to a settings XML file in specific locations on disk.
Put simply, this requires another prerequisite arbitrary file write vulnerability to be reachable.
This isn’t “zero click” unless we’re going under the assumption that an attacker already has full control over my machine before that. At best, this is a persistence mechanism, not initial access.
- jcarrano 3mo agoWe are living through CVE-inflation (or CVEflation?) where anyone who discovers a bug using LLMs will instantly claim it is huge security hole.
- ringzeropirate 3mo agoThis is a third bug that emerged following a maintainer fix. If you check my profile, you might be able to reconsider your statement.
- ringzeropirate 3mo agosame privileges, the attacker does not have full control of the system.