3 ms·
How is this possible? Can someone point me in the direction of what mechanism is used here. If I open a pdf in chrome for example am I opening myself up to thi
by aeroaero 4y ago
How is this possible? Can someone point me in the direction of what mechanism is used here.
If I open a pdf in chrome for example am I opening myself up to this kind of attack?
- Renaud 4y agoI would say first thing is to disable Windows Explorer from hiding the extension of files. From what I understand, it was an executable inside a zip attachment to an email disguising itself as a partnership proposal from a reputable source. The file inside the zip probably had a .pdf.exe extension. By default, Windows Explorer would show it as a .pdf, making it easy to run by mistake.
- richardjam73 4y agoThat should be stopped by the smartscreen prompt which is pretty hard to bypass by accident.
- andreareina 4y agoWait it wasn't an executable pdf that escaped the sandbox, it was a *.pdf.exe?? Why does Windows even still have this vulnerability?
- TheLoafOfBread 4y agoPDF can run JavaScript
- deleted 4y ago[deleted]