3 ms·
>is said to never even have been a zero day, i.e. before it was publicly released, Microsoft was forewarned and released a patch. Which is nonsense. It was an
by cf498 7y ago
>is said to never even have been a zero day, i.e. before it was publicly released, Microsoft was forewarned and released a patch.
Which is nonsense. It was an exploit that was actively used for at least 5 years before Microsoft was informed about it. The "not a zeroday" is pretty close to doublespeak. There is nothing to sugarcoat here. It was a zeroday that was exploited for years and Microsoft wasnt informed until the very end. All the while millions of devices were vulnerable. I have to say I am having a hard time assuming good faith when people make such statements, here of all places.
A vulnerability is a zero day until the day the maker is informed about it. Its not an ambiguous definition.
- sneak 7y agoThe dangerous assumption here is that nobody else ever got hold of the EternalBlue exploit outside of those they wanted to have it. This is a bad assumption. Others could have developed it independently, or intercepted it from NSA usage, and used it for years prior to the leak of the tools. Hoarding 0days makes everyone less safe.