logoalt Hacker News

gcryesterday at 1:13 PM1 replyview on HN

What does “unverified protocols” mean? Does Windows have an exe:// url scheme that fetches and runs executable binaries or something?


Replies

gruezyesterday at 1:19 PM

Yes? ShellExecute opens a url if you pass in a url, opens a file if you pass in a path, and runs an .exe if that file is an .exe. Windows also supports SMB paths, so combine that together and you have a RCE

show 1 reply