Defense in depth — the Microsoft way (part 88): a SINGLE command line shows about 20, 000 instances of CWE-73 –
– [[{“value”:”
Posted by Stefan Kanthak on Sep 28
Hi @ll,
<https://cwe.mitre.org/data/definitions/73.html>
CWE-73: External Control of File Name or Path
is a well-known and well-documented weakness.
<https://seclists.org/fulldisclosure/2020/Mar/48> as well as
<https://skanthak.homepage.t-online.de/offender.html> demonstrate how to
(ab)use just one instance of this weakness (introduced about 7 years ago
with Microsoft Defender, so-called “security software”) due to…
“}]] – Read More – Full Disclosure