this post was submitted on 22 Jun 2023
12 points (100.0% liked)

Cybersecurity

5668 readers
84 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
 

I only know about CVE-2013-3900 (WinVerifyTrust) which allows modified files to pass signature check unless you tweak registry to enable patches.

I think there must be other instances like this where Microsoft won’t fix vulnerability or chooses insecure defaults, is there a list?

you are viewing a single comment's thread
view the rest of the comments
[–] privsecfoss@feddit.dk 3 points 1 year ago* (last edited 1 year ago)

Don't know precisely, but hear from time to time that Microsoft is notorious for not patching in time in many cases, leaving vulnerabilities for months and sometimes years. I am pretty sure that MS just kinda gave up on the vulnerabilities MimiKatz exploits, so if the bad guys are on your network and you use MS infra it's pretty much a question of time before they get admin credentials.