Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. being sent a sketchy file and then asked to click on a link in it isn't "remote" code execution actually

being sent a sketchy file and then asked to click on a link in it isn't "remote" code execution actually

Scheduled Pinned Locked Moved Uncategorized
3 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • invoxiplaygames.uk@bsky.brid.gyI This user is from outside of this forum
    invoxiplaygames.uk@bsky.brid.gyI This user is from outside of this forum
    invoxiplaygames.uk@bsky.brid.gy
    wrote last edited by
    #1

    being sent a sketchy file and then asked to click on a link in it isn't "remote" code execution actually

    gsuberland@chaos.socialG 1 Reply Last reply
    0
    • invoxiplaygames.uk@bsky.brid.gyI invoxiplaygames.uk@bsky.brid.gy

      being sent a sketchy file and then asked to click on a link in it isn't "remote" code execution actually

      gsuberland@chaos.socialG This user is from outside of this forum
      gsuberland@chaos.socialG This user is from outside of this forum
      gsuberland@chaos.social
      wrote last edited by
      #2

      @invoxiplaygames.uk i was thinking about this for a while and I think my opinion is that it's ok to call it RCE (you're tricking the user into downloading and running remote code) because we currently lack taxonomic specificity around the "it's an interactive trick based on subverting user expectations, not traditional RCE" aspect of it.

      the key problem is calling this class of document-based code execution bugs "remote", when the actual exploitation vector is inherently filesystem-local.

      buherator@infosec.placeB 1 Reply Last reply
      0
      • gsuberland@chaos.socialG gsuberland@chaos.social

        @invoxiplaygames.uk i was thinking about this for a while and I think my opinion is that it's ok to call it RCE (you're tricking the user into downloading and running remote code) because we currently lack taxonomic specificity around the "it's an interactive trick based on subverting user expectations, not traditional RCE" aspect of it.

        the key problem is calling this class of document-based code execution bugs "remote", when the actual exploitation vector is inherently filesystem-local.

        buherator@infosec.placeB This user is from outside of this forum
        buherator@infosec.placeB This user is from outside of this forum
        buherator@infosec.place
        wrote last edited by
        #3
        @gsuberland @invoxiplaygames.uk Calling this RCE is at least consistent with MS's own taxonomy (see previous Office vulns). CVSS UI:R is also a meaningful datapoint for those parsing their feed.
        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups