微软与研究员激烈交锋后,紧急修复两枚高危零日漏洞

AI导读

微软周二修复了两个高严重性零日漏洞,这些漏洞由化名“Nightmare Eclipse”的研究员披露。该研究员此前与微软就漏洞披露达成协议,但声称微软违背约定,导致其公开了包含概念验证代码的漏洞,可能被野外利用。

AI Prism 智棱 - 机器人 分类封面图
Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant. Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-days that had the potential to be exploited in the wild. The researcher has said the disclosures, which included proof-of-concept code, came after Microsoft reneged on an arrangement the two made regarding vulnerabilities they had discussed. Disclosure drama “But someone violated our agreement and left me homeless with nothing,” Nightmare Eclipse wrote in March. “They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”Read full article Comments

内容声明

本文内容基于公开市场信息与媒体报道进行整理,部分观点来自社区讨论。如涉及事实性问题,欢迎通过 xurj005@163.com 与我们指正,我们将及时核实并更新。