Why is Microsoft updating their text editors!? | TheStandup

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A podcast discussion covering two recent security exploits in Windows text editors. The first involves Microsoft Notepad, which added markdown parsing and used ShellExecuteExW to open links without sanitization, allowing arbitrary code execution via crafted file:// URLs in markdown links. The second, more serious exploit targeted Notepad++ users: state-sponsored attackers compromised the WinGUp auto-updater's hosting server, then selectively served a malicious update only to high-value IP targets. The malicious package included a legitimate BitDefender executable renamed as a Bluetooth service, with its DLLs replaced by exploit payloads — a sophisticated DLL hijacking attack that was extremely difficult to detect due to its targeted nature.

30m watch time

Sort: