4 ms·
This is the core problem. Everybody is discussing the crash dump and the exfil, but the core problem is that Microsoft neither validated the validity of keys (t
by alphager 3y ago
This is the core problem. Everybody is discussing the crash dump and the exfil, but the core problem is that Microsoft neither validated the validity of keys (the leaked key was already invalid) nor the context of the key usage (the key wasn't allowed to generate admin tokens). They just checked if the key was signed by the Microsoft CA.
This is something that's incredibly obvious in a code review.