I think @natashenka and I just discovered the worst Windows remote code exec in recent memory. This is crazy bad. Report on the way. 


-
-
Replying to @taviso @natashenka
Attack works against a default install, don't need to be on the same LAN, and it's wormable.
28 replies 456 retweets 610 likes -
Replying to @taviso @natashenka
I assume it still requires *inbound* (routed) connectivity? I.e. something typical NATs and firewalls stop.
2 replies 0 retweets 1 like
Because if this can be exploited by outbound connections, the world is going to burn. Especially if a web browser can trigger them.
4:37 AM - 6 May 2017
0 replies
0 retweets
5 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.