|
You are here |
parsiya.net | ||
| | | | |
zero.lol
|
|
| | | | | [AI summary] A technical article detailing an arbitrary code execution exploit against EA's Origin client through malicious custom URI schemes and Windows shortcut files. | |
| | | | |
mazinahmed.net
|
|
| | | | | Application and Infrastructure Security Engineering | |
| | | | |
positive.security
|
|
| | | | | Chaining a misconfiguration in IE11/Edge Legacy with an argument injection in a Windows 10/11 default URI handler and a bypass for a previous Electron patch, we developed a drive-by RCE exploit for Windows 10. The main vulnerability in the ms-officecmd URI handler has not been patched yet and can also be triggered through other browsers (requires confirmation of an inconspicuous dialog) and desktop applications that allow URI opening. | |
| | | | |
www.triskelelabs.com
|
|
| | | Critical SharePoint flaws vulnerabilities CVE-2025-53770 and CVE-2025-53771 allow Remote Code Execution. | ||