Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You two seem to not understand still, please re-read my comment.

The point is this is allowing code execution within the kernel of windows. It doesn't even reach the IIS userland process.



I actually don't because I have no clue how Windows Server works. So this attack hits the kernel and the context is low level, right?


Not sure if I am not clear enough but yes, it 'hits the kernel and the context is low level'. As low as it can get on Windows.


[deleted]


I have trouble understanding what you want to say but I did not say what you quoted me with. Please don't put words in my mouth.

The title was giving people the wrong impression about the severity of the vulnerability. This has nothing to do with "avoid giving people ideas" which would be stupid anyways.


My windows knowledge is rusty and outdated but... do you mean that code runs in ring 0? that "kernel space"?


Yes




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: