If I'm reading the disclosure correctly, the issue is:
-
RE: https://tech.lgbt/@solonovamax/116049115040950367
If I'm reading the disclosure correctly, the issue is:
- Windows Notepad is more than just a plain text editor now.
- In particular, it has a markdown preview feature, including clickable links.
- But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.So, don't open strange files & then click links. (And update Windows regularly.)
-
RE: https://tech.lgbt/@solonovamax/116049115040950367
If I'm reading the disclosure correctly, the issue is:
- Windows Notepad is more than just a plain text editor now.
- In particular, it has a markdown preview feature, including clickable links.
- But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.So, don't open strange files & then click links. (And update Windows regularly.)
@AmeliaBR It took them 25 years, but Microsoft finally figured out how to add RCE to notepad.exe.
-
RE: https://tech.lgbt/@solonovamax/116049115040950367
If I'm reading the disclosure correctly, the issue is:
- Windows Notepad is more than just a plain text editor now.
- In particular, it has a markdown preview feature, including clickable links.
- But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.So, don't open strange files & then click links. (And update Windows regularly.)
@AmeliaBR “So, don't open strange files & then click links.” Sage advice for all circumstances!
-
RE: https://tech.lgbt/@solonovamax/116049115040950367
If I'm reading the disclosure correctly, the issue is:
- Windows Notepad is more than just a plain text editor now.
- In particular, it has a markdown preview feature, including clickable links.
- But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.So, don't open strange files & then click links. (And update Windows regularly.)
@AmeliaBR there was a 'phoning home' thing in Windows Notepad too if I remember correctly, don't have a source to hand. Possibly an unwanted OneDrive sync thing?
-
undefined oblomov@sociale.network shared this topic
-
RE: https://tech.lgbt/@solonovamax/116049115040950367
If I'm reading the disclosure correctly, the issue is:
- Windows Notepad is more than just a plain text editor now.
- In particular, it has a markdown preview feature, including clickable links.
- But, it doesn't have full web browser security processes for what to do if you click on a link with a protocol that triggers a local application. It gets treated as if the user was directly running that application.So, don't open strange files & then click links. (And update Windows regularly.)
@AmeliaBR or remove notepad... Or Windows 😉