3 ms·
Is there value in requesting a CVE for a service that only Microsoft runs? What's a user supposed to do with that?
by thombles 1y ago
Is there value in requesting a CVE for a service that only Microsoft runs? What's a user supposed to do with that?
- fulafel 1y agoCVEs are supposed to be unambigous references to vulnerabilities for communication, nothing more. So you can say stuff like "this happened was before CVE-XXXX was fixed, do we need to notify anyone about the risk of undetected insider info access?"