Just sent this zero-day to @msftsecresponse :->pic.twitter.com/wBCeEs619k
-
-
Replying to @steventseeley @msftsecresponse
Isn't MSC known to be inherently dangerous, though? Users get warnings before allowing downloads, the MSC handler in Windows obeys the MoTW, and there are public examples that run code via MSC files. I modified it to just run calc.exe in this case.pic.twitter.com/8tgqV65ecQ
2 replies 0 retweets 9 likes
Refer to the list of unsafe (able to run code) files for IE: https://support.microsoft.com/en-us/help/291369 … MSC is listed.
3:32 PM - 19 Jul 2019
0 replies
0 retweets
3 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.