WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
-
@freya that's fair! If you can get it working in a VM or something and post bug reports, it will do so so so much to help! I hope it gets better for you so you can get away from the hell company.

@malachai I have had better and more consistent accessibility on my Solaris 10 SPARC box than with any and all modern Linuxen
-
@solonovamax non vibe coders have a long and lucrative career ahead of them cleaning up this mess
-
@solonovamax "An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files."
Why have they made their plaintext editor render markdown??
@Kiloku @solonovamax Because they removed WordPad and then realized they didn't have anything that filled the Niche that WordPad did. And the solution, instead of bringing back WordPad, was to AI Re-Write Notepad into WordPad Featuring AI.
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax Windows is getting that bad? Crazy what happens when you use ai to code an OS.
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
And for once, adding AI to the app was not to blame! (Although the issue was introduced in the same batch that added AI, so I'd still count it) -
@solonovamax I don’t understand how this could even happen. It’s a markup language. Are the calling `eval` on the markdown output?
-
@solonovamax "An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files."
Why have they made their plaintext editor render markdown??
@Kiloku @solonovamax more interesting, how the fuck do you cause an RCE vulnerability in a markdown renderer?
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
Isn't Notepad supposed to be PLAIN TEXT editor? But oh, they shoved in LLM support and in that same update they added parsing and presentation formatted text.
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax wait til you hear about calculator.exe
-
@solonovamax non vibe coders have a long and lucrative career ahead of them cleaning up this mess
@AVincentInSpace @solonovamax never do your job too well.
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
WHY DO MULTIPLE SIMPLE TEXT EDITORS HAVE REMOTE CODE EXECUTION IN GENERAL
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax Culture Ship name!
-
@malachai it has many accessibility features, yes, unfortunately the screenreader (which is what I need) is a glitchy unstable mess, and modern UI frameworks make this worse, as does Wayland and Pipewire and suchlike. there's no large amount of funding going into Linux desktop accessibility, and it's such a moving target at this point that getting stable accessibility is really hard
@malachai @freya That sucks! And this should be shouted at all of the eejits who are pushing for the oh-so-shiny new stuff just because it's new, and it almost works for me, why don't you like it, and the old stuff is old.
Yes, it is old but it works, also for people who need special things, like screen readers and what not. At least in an IT forum I loosely follow some of the residents brought that up, regarding wayland. (and pipwire is a hot mess at least when I tried) -
@malachai @freya That sucks! And this should be shouted at all of the eejits who are pushing for the oh-so-shiny new stuff just because it's new, and it almost works for me, why don't you like it, and the old stuff is old.
Yes, it is old but it works, also for people who need special things, like screen readers and what not. At least in an IT forum I loosely follow some of the residents brought that up, regarding wayland. (and pipwire is a hot mess at least when I tried) -
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax why didn't they just embed Internet Explorer into Notepad
-
undefined filobus@sociale.network shared this topic
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax
What's next, remote code execution in MS Paint? -
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax exploit script or gtfo
lets fucking go -
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY
@solonovamax They just had to add the fucking Copilot, huh? 🙄🙄 I'm sure that has nothing to do with it.. /s
-
WINDOWS NOTEPAD APP REMOTE CODE EXECUTION VULNERABILITY