11 ms·
Quite interesting the response from MITRE: `It is not considered a security vulnerability because of how it requires a local attacker with privileges present to
by ygouzerh 16d ago
Quite interesting the response from MITRE: `It is not considered a security vulnerability because of how it requires a local attacker with privileges present to make it so`.
I didn't knew about that rationale. I thought Defense-in-Depth was all about that, preventing security incidents even when an attacker start to get some elevated privileges on the system?
If not, that's quite a practical reference for future CyberSec meetings.