Clicking unknown links is always a bad idea, but a CVE for that? I dunno....
Clicking unknown links is always a bad idea, but a CVE for that? I dunno....
Rewriting it to integrate AI and some bells and whistles recklessly and having a CVE is tragicomic if you ask me.
So yes, MS will likely denounce this as not their problem and move on.
But yeah, pedantic terminology aside, what a stupid stupid error. In notepad, of all things, reading text files should be safe. It reminds me of the WMF failure. "No you can't get a virus from playing a video" is what I would tell people. And then microsoft in their infinite wisdom said "Herp Derp, why don't we package the executable video decoder right in the video file. It will make searching for a codec a thing of the past" Sigh, smooth move microsoft, thanks for making a liar out of me.
Last month it was the term "supply chain attack" that was abused to describe a situation where some vulnerable dependency could be abused in a downstream component. I guess every weakness in the Linux kernel is now a "supply chain attack" because it was in the supply chain and there is an attack, never mind that the term was originally about e.g. the liblzma/xz situation (specific attacks on a supply chain component, with no other purpose than attacking a downstream vendor)
I know I can't stop language change but I am getting a bit tired of how many tech people (who know better) go along with fear term inflation
It'd be the same to upload a file to a web server that gets to be run by the said web server, except this time it's done with "notepad.exe"