Hacker News new | past | comments | ask | show | jobs | submit login
How the first Microsoft Office 2007 vulnerability was discovered (twitter.com/laughing_mantis)
16 points by niklasbuschmann 7 months ago | hide | past | favorite | 4 comments




TL;DR:

The author, working at eEye in 2006, found what seemed like a big zero-day in Office 2007, but it only worked with a debugger attached.

Not wanting to admit it wasn't a real exploit, the eEye team pulled all-nighters for several days and found a real bug in Microsoft Publisher where SafeInt wasn't enabled for a specific structure.

They found a valid exploit (CVE-2007-1754) which got patched in MS07-037. And he regrets causing Microsoft's David LeBlanc to cut his vacation short.


That got obnoxious quickly when the "Hey look everybody I'm drunk! Am I not the most awesome!" tweets got mixed in...

https://threadreaderapp.com/thread/1799457232607985698.html


I couldn’t even be bothered to read past when he started yapping about the bartender giving him more drinks. I’d rather read the coherent version after the hangover is gone.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: