Vishwa
@vishwaraj101
Pwnartist, infosec enthusiast, also on both the sides!
ID: 1092836365
15-01-2013 18:04:53
844 Tweet
656 Takipçi
1,1K Takip Edilen
I bypassed user approvals and achieved RCE in VS Code Copilot by flipping 4 bits. Find out how: jro.sg/CVEs/copilot/ Thanks to Microsoft Security Response Center for rapidly triaging and patching this vulnerability.
404 page to RCE. A report by spaceraccoon | Eugene Lim He chained two old CVEs to achieve RCE: - Found a 404 page mentioning an obscure CMS, discovered /josso/signin login - Triggered CVE-2007-0450 (directory traversal in mod_proxy) using a %5C../ to bypass the internal proxy - Reached