This person is getting to be fucking annoying.
The title is definitely not as described, only applies to Windows (I think), and won’t work without a permissions escalation.
The only reason it’s classified as a CVE is because they requested it be such.
There are no payload attacks proven here, or PoC attack code. This person has been posting pretty basic “hacks” for a few years, and makes a mountain out of an anthill every damn time.
🙄 Ugh
only applies to Windows (I think)
Well yeah, its a vulnerability in the windows software. Nothing they said implied otherwise.
and won’t work without a permissions escalation.
I dont think thats true, could you explain why that would be? This article mentioned no need for a permissions escalation. In fact it seems that the RCE is automatically run as administrator by the driver process.
“This only applies to the most widely used OS and won’t work without someone clicking grant admin permissions which most people probably do blindly.”
🙄 Ugh
How could it apply to any other operating system than Windows? Pre installed drivers, in a pre installed OS? They probably don’t even write drivers for other OS
Wine or compatibility layers.
This person is getting to be fucking annoying.
🤷♂️ Sounds like a job for the “block user” feature… 🤔