Blue screen on Chrome bug here by @jonasLyk.https://twitter.com/jonasLyk/status/1350903421507936256 …
-
-
Replying to @vysecurity @jonasLyk
I wouldn't call this a Chrome bug. It's Windows that crashes when a certain path is accessed. It's hard to blame Chrome for that.
1 reply 0 retweets 0 likes -
True. It’s a file path bug thanks. I only tried it in chrome that’s all.
1 reply 0 retweets 0 likes -
Replying to @vysecurity @jonasLyk
Will Dormann Retweeted Will Dormann
There are plenty of ways to cause Windows to access a path. e.g., opening an ISO you downloaded. It's hard to blame whatever browser you used to take that action.https://twitter.com/wdormann/status/1351197554747318273 …
Will Dormann added,
0:11Will Dormann @wdormannSpecifically, I didn't see a way to get legacy Edge to obey the '.' in \\.\globalroot\device\condrv\kernelconnect However, as with the NTFS corruption bug, this can be triggered by something as innocuous as opening a file from a website. e.g., an ISO file: pic.twitter.com/AQL7Flfpk6Show this thread1 reply 0 retweets 0 likes -
Yeah. More keen to just know if it works in Outlook
2 replies 0 retweets 0 likes -
Replying to @vysecurity @jonasLyk
A few years ago, this would have been possible with no interaction beyond previewing an email in Outlook that has an OLE object. But they fixed that vector. Probably requires a click by now.https://insights.sei.cmu.edu/cert/2018/04/automatically-stealing-password-hashes-with-microsoft-outlook-and-ole.html …
1 reply 0 retweets 2 likes
Jonas L Retweeted Jonas L
there is also the entire vulnerability class of fake dir listings. https://twitter.com/jonasLyk/status/1303486470360125440 … that can cause unexspected things to open
Jonas L added,
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.