…“The vulnerable driver ships with every version of Windows, up to and including Server 2025,” Adam Barnett, lead software engineer at Rapid7, said. “Maybe your fax modem uses a different chipset, and so you don’t need the Agere driver? Perhaps you’ve simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator.”…
It’s interesting that this supposedly goes back to Windows 3.1 and the original release…
I was curious about the “every version ever shipped.”
This gets really old school.
Personally I blame Dave Plummer.
Ah yes the 0-decade vulnerability…
Boi will I miss the ever-encompasing shield of Microsoft when my Windows 10 stops receiving updates…
makes you wonder if/how/by who its been used all these years
I expect it’s stuff like ATMs, Coinstar machines. Things that may need to phone home regularly but don’t need to sit online constantly.
It will be interesting what happens with this Windows 10 end of support, this just happens to crop up the day after support ends.
yeah, the timing is ‘interesting’
They will continue to releases major security updates for Windows 10 as long as it has double digit installed base share.
Yeah, they did the same for Win7 for a long time. Win7 was so widely used (and people were so hesitant to upgrade after the awful 8/8.1 mess) that like 25-30% of all the computers in the world were still using it several years after support officially ended. It forced MS to continue issuing critical vulnerability patches for Win7, long after support officially ended. Because they didn’t want to be responsible for creating a massive “literally a quarter of all PCs in the world” botnet when they stopped patching things.
Fixed and required physical access to the machine. If someone malicious has physical access to your machine you’re already done.
Does it mean you don’t think login password with physical token with disk encryption work?
The attacker had to already be logged in to the machine for this exploit.
Thanks for clarifying, guess you meant “required physical access to the machine AND being logged in.” then which makes a huge difference.
deleted by creator
Nope. You don’t need to be using the driver. The article explains that an attacker call upon it and exploit it simply because it is there.
If true:
Totally none did wait for most popular win10 end supports…
If fake:
Totally none sus this for being fake scarecrow against anyone who would like to stay on non-service, standalone system.








