home.social

#exploitwednesday — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #exploitwednesday, aggregated by home.social.

fetched live
  1. Here are the results of #ghidriff's VersionTrackingDiff ran on the latest patch of afd.sys (likely as the result of CVE-2025-21418):

    https://gist.github.com/v-p-b/458475d0c7f8aaf6496b5168c04ea262

    The change seems to affect a single but significant API (AfdAccept()), my initial guess is this was a locking issue.

    #ExploitWednesday
  2. Here are the results of #ghidriff's VersionTrackingDiff ran on the latest patch of afd.sys (likely as the result of CVE-2025-21418):

    https://gist.github.com/v-p-b/458475d0c7f8aaf6496b5168c04ea262

    The change seems to affect a single but significant API (AfdAccept()), my initial guess is this was a locking issue.

    #ExploitWednesday
  3. Has anyone looked into the "Advanced Installers" (...ai.dll) distributed via Windows Updates? #ExploitWednesday
  4. Has anyone looked into the "Advanced Installers" (...ai.dll) distributed via Windows Updates? #ExploitWednesday
  5. Cumulated external DNS-queries to our domains. Did someone whisper #exploitWednesday? #infosec