3 ms·
Not really related, but I reported a kernel-level bug to Microsoft over a year ago. It seems like it could be exploitable (it's easy enough to trigger from user
by wfunction 12y ago
Not really related, but I reported a kernel-level bug to Microsoft over a year ago. It seems like it could be exploitable (it's easy enough to trigger from user-mode, but I'm not sure how easy it is to exploit for malicious uses other than DoS attacks). I received a reply that they would look into it, and that in the meantime I shouldn't disseminate it. However I'm fairly sure it hasn't been fixed, and it may never be. Should I make it public? Why or why not?
- guardian5x 12y agoIn my opinion, you should make it public. Over one year is more than enough time to respond. At least once its public it will get pressure to get fixed.
- wfunction 12y agoI should mention that I don't really want to put myself on a possible internal blacklist either (if I were to get a job there or something in the future)... I'd like it to get fixed but I'm hoping there's a better way than publishing it and ticking someone off internally, I just don't know what way.
- acdha 12y agoIf you've confirmed an exploit, what I normally prefer is to send a followup message stating that you intend to publish in a month and request a comment. That gives them time to say “Oops, did we forget to tell you it's not exploitable?” or “It was quietly fixed two months ago”.
- wfunction 12y agoI don't have a confirmed exploit (other than a DoS, but I don't think that's very interesting). I think it may be exploitable but I haven't looked into the "how" and don't really intend to. I just know it's a hole.