Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Microsoft: I have made Notepad✨

Microsoft: I have made Notepad✨

Scheduled Pinned Locked Moved Uncategorized
11 Posts 6 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tess@mastodon.socialT This user is from outside of this forum
    tess@mastodon.socialT This user is from outside of this forum
    tess@mastodon.social
    wrote last edited by
    #1

    Microsoft: I have made Notepad✨

    Security researchers: You fucked up a perfectly good plaintext editor is what you did. Look at it. It's got RCEs.

    favicon

    (www.cve.org)

    jbaggs@infosec.exchangeJ S kcarruthers@infosec.exchangeK 0x00string@infosec.exchange0 4 Replies Last reply
    2
    0
    • tess@mastodon.socialT tess@mastodon.social

      Microsoft: I have made Notepad✨

      Security researchers: You fucked up a perfectly good plaintext editor is what you did. Look at it. It's got RCEs.

      favicon

      (www.cve.org)

      jbaggs@infosec.exchangeJ This user is from outside of this forum
      jbaggs@infosec.exchangeJ This user is from outside of this forum
      jbaggs@infosec.exchange
      wrote last edited by
      #2

      @tess I'm going to absolutely lose my shit if this ever happens to stock vi. (No, not vim, though I like the context highlighting.)

      1 Reply Last reply
      0
      • tess@mastodon.socialT tess@mastodon.social

        Microsoft: I have made Notepad✨

        Security researchers: You fucked up a perfectly good plaintext editor is what you did. Look at it. It's got RCEs.

        favicon

        (www.cve.org)

        S This user is from outside of this forum
        S This user is from outside of this forum
        slotos@toot.community
        wrote last edited by
        #3

        @tess

        > How could an attacker exploit this vulnerability?
        >
        > An attacker could _trick a user into clicking a malicious link_ inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files.

        That’s not an RCE, is it?

        heretochewgum@fosstodon.orgH 1 Reply Last reply
        0
        • S slotos@toot.community

          @tess

          > How could an attacker exploit this vulnerability?
          >
          > An attacker could _trick a user into clicking a malicious link_ inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files.

          That’s not an RCE, is it?

          heretochewgum@fosstodon.orgH This user is from outside of this forum
          heretochewgum@fosstodon.orgH This user is from outside of this forum
          heretochewgum@fosstodon.org
          wrote last edited by
          #4

          @slotos @tess

          CNA: Microsoft Corporation.
          Published: 2026-02-10
          Updated: 2026-02-11

          Title: Windows Notepad App Remote Code Execution Vulnerability
          Description

          Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code over a network

          S 1 Reply Last reply
          0
          • heretochewgum@fosstodon.orgH heretochewgum@fosstodon.org

            @slotos @tess

            CNA: Microsoft Corporation.
            Published: 2026-02-10
            Updated: 2026-02-11

            Title: Windows Notepad App Remote Code Execution Vulnerability
            Description

            Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code over a network

            S This user is from outside of this forum
            S This user is from outside of this forum
            slotos@toot.community
            wrote last edited by
            #5

            @HereToChewGum Read the details. There’s no remote execution capability, but rather a user can be tricked into executing code from a remote source.

            RCE, as I understand it, doesn’t involve user interaction. This is an ACE, but not an RCE.

            heretochewgum@fosstodon.orgH 1 Reply Last reply
            0
            • S slotos@toot.community

              @HereToChewGum Read the details. There’s no remote execution capability, but rather a user can be tricked into executing code from a remote source.

              RCE, as I understand it, doesn’t involve user interaction. This is an ACE, but not an RCE.

              heretochewgum@fosstodon.orgH This user is from outside of this forum
              heretochewgum@fosstodon.orgH This user is from outside of this forum
              heretochewgum@fosstodon.org
              wrote last edited by
              #6

              @slotos

              The ability to trigger arbitrary code execution (ACE) over a network (especially via a wide-area network such as the Internet) is often referred to as remote code execution (RCE or RCX). (Wikipedia)

              S 1 Reply Last reply
              0
              • heretochewgum@fosstodon.orgH heretochewgum@fosstodon.org

                @slotos

                The ability to trigger arbitrary code execution (ACE) over a network (especially via a wide-area network such as the Internet) is often referred to as remote code execution (RCE or RCX). (Wikipedia)

                S This user is from outside of this forum
                S This user is from outside of this forum
                slotos@toot.community
                wrote last edited by
                #7

                @HereToChewGum

                It’s not triggered over the network. Read the fine print!

                Are you using Grok to talk to me or something?

                heretochewgum@fosstodon.orgH 1 Reply Last reply
                0
                • S slotos@toot.community

                  @HereToChewGum

                  It’s not triggered over the network. Read the fine print!

                  Are you using Grok to talk to me or something?

                  heretochewgum@fosstodon.orgH This user is from outside of this forum
                  heretochewgum@fosstodon.orgH This user is from outside of this forum
                  heretochewgum@fosstodon.org
                  wrote last edited by
                  #8

                  @slotos

                  I was hoping you would explain what you mean. It is possible that having read the fine print I misunderstood or simpy missed something.

                  MS describes it as a remote code execution vulnerability.

                  So maybe you could explain why they are wrong.

                  Hopefully being able to do that without being insulting is within the apparently limited scope of your social interaction ability?

                  S 1 Reply Last reply
                  0
                  • R relay@relay.an.exchange shared this topic
                  • heretochewgum@fosstodon.orgH heretochewgum@fosstodon.org

                    @slotos

                    I was hoping you would explain what you mean. It is possible that having read the fine print I misunderstood or simpy missed something.

                    MS describes it as a remote code execution vulnerability.

                    So maybe you could explain why they are wrong.

                    Hopefully being able to do that without being insulting is within the apparently limited scope of your social interaction ability?

                    S This user is from outside of this forum
                    S This user is from outside of this forum
                    slotos@toot.community
                    wrote last edited by
                    #9

                    @HereToChewGum If you want an explanation, bloody ask for one. Quoting text your interlocutor went through is a passive aggressive insult at best.

                    Especially given how you evidently didn’t put even a shred of effort into reading the damn CVE and its sources yourself.

                    1 Reply Last reply
                    0
                    • tess@mastodon.socialT tess@mastodon.social

                      Microsoft: I have made Notepad✨

                      Security researchers: You fucked up a perfectly good plaintext editor is what you did. Look at it. It's got RCEs.

                      favicon

                      (www.cve.org)

                      kcarruthers@infosec.exchangeK This user is from outside of this forum
                      kcarruthers@infosec.exchangeK This user is from outside of this forum
                      kcarruthers@infosec.exchange
                      wrote last edited by
                      #10

                      @tess 🤣🙀🤦‍♀️

                      1 Reply Last reply
                      0
                      • pixelate@tweesecake.socialP pixelate@tweesecake.social shared this topic
                      • tess@mastodon.socialT tess@mastodon.social

                        Microsoft: I have made Notepad✨

                        Security researchers: You fucked up a perfectly good plaintext editor is what you did. Look at it. It's got RCEs.

                        favicon

                        (www.cve.org)

                        0x00string@infosec.exchange0 This user is from outside of this forum
                        0x00string@infosec.exchange0 This user is from outside of this forum
                        0x00string@infosec.exchange
                        wrote last edited by
                        #11

                        @tess its a local client-side bug, not an rce, so really you can also mock them for doing some 15yo bug embellishment shit too

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.infosec.exchange shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups