Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Microsoft won’t say if it'll patch critical Windows vulnerability under exploit (arstechnica.com)
2 points by samizdis on June 7, 2022 | hide | past | favorite | 1 comment


This makes me anxious, but am I overreacting?

Normally, these attacks need the target to open the document and enable the use of macros. Follina, by contrast, doesn't require the target to open the document, and there's no macro to allow. The simple act of the document appearing in the preview window, even while protected view is turned on, is enough to execute malicious scripts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: