3 ms·
This flaw was packaged in a doc and spear-phished to specific people to achieve a specific goal. You are confusing features like "embedded in a .doc" and "unreg
by trotsky 15y ago
This flaw was packaged in a doc and spear-phished to specific people to achieve a specific goal. You are confusing features like "embedded in a .doc" and "unregulated by things like flashblock or noscript" with a limitation.
While the initial attack is uninterested in you, these things spread widely. There is nothing that has been reported that suggests it is limited to this delivery vehicle - I would assume it is not. In my experience, 2nd or 3rd order exploitations will be active before an adobe fix is released.
- seanalltogether 15y agoI think his point was that this exploit was done outside of a browser sandbox, which places it in a whole new category of security issues. You could just as easily say this is microsofts fault for not applying stricter policies on activex controls within office products.