6 ms·
How about that time Avast gave you RCE by simply adding HTML to the CN field of an invalid certificate?[^1] Or when TrendMicro added an unauthenticated listener
by runlevel1 3y ago
How about that time Avast gave you RCE by simply adding HTML to the CN field of an invalid certificate?[^1] Or when TrendMicro added an unauthenticated listener that would exec anything you sent it?[^2]
[1]: https://www.theregister.com/2015/10/06/google_zero_hacker_reports_remote_exec_hole_in_avast_antivirus/ https://www.theregister.com/2015/10/06/google_zero_hacker_re...
[2]: https://bugs.chromium.org/p/project-zero/issues/detail?id=693&q=mitm&can=1 https://bugs.chromium.org/p/project-zero/issues/detail?id=69...