Nice, my first CVE not in a MS product is incoming: Development has confirmed this is a vulnerability and is working on a fix. We have assigned CVE-2020-8327 to the vulnerability. From lenovo
-
Show this thread
-
Was in doubt if in scope of MS bounties as it was a PNP driver dual signed with a ms cert and updated through windows update. First dismissed because wrong analysis making them think exploitation required admin privs.
1 reply 0 retweets 1 likeShow this thread
I showed them why that was not the case, then it was dismissed because not in scope. So I submitted it to Lenovo, then at least I get a cve on my resume :)
2:56 PM - 2 Apr 2020
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.