Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
pheonix
pheonix
@pheonix@hachyderm.io  路  activity timestamp 6 hours ago

They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

This CVE is an 8.8 severity RCE in Notepad of all things lmao.

Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 馃槶

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

#noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

screenshot from the CVE page
screenshot from the CVE page
screenshot from the CVE page

Security Update Guide - Microsoft Security Response Center

  • Copy link
  • Flag this post
  • Block
JKB
JKB
@jkb@gotosocial.jkbockstael.be replied  路  activity timestamp 4 hours ago

@pheonix According to the report you have to click a link in the file, just loading it won't compromise the system.

  • Copy link
  • Flag this comment
  • Block
Gabriele Svelto
Gabriele Svelto
@gabrielesvelto@mas.to replied  路  activity timestamp 5 hours ago

@pheonix *vibe-coding intensifies*

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.2-alpha.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct