Brutkey

K. Reid Wightman :verified: 🌻🌻 :donor: :clippy:
@reverseics@infosec.exchange

@cR0w@infosec.exchange I am actually super duper confused: AV:L and UI:N and PR:N. That is theoretically an impossible combination.


cR0w
@cR0w@infosec.exchange

@reverseics@infosec.exchange I guess their thought is that a user leaves Outlook open and is sent a malicious email and it automatically pops up in the preview pane, they didn't have to interact with it and the attacker didn't need privs to send the email. Just guessing at the logic there.

K. Reid Wightman :verified: 🌻🌻 :donor: :clippy:
@reverseics@infosec.exchange

@cR0w@infosec.exchange You need local access, but no privileges, nor does the user have to click anything.

So if you have code execution on the system, you get code execution on the system I guess. QED.