logoalt Hacker News

gruezyesterday at 1:19 PM1 replyview on HN

Yes? ShellExecute opens a url if you pass in a url, opens a file if you pass in a path, and runs an .exe if that file is an .exe. Windows also supports SMB paths, so combine that together and you have a RCE


Replies

eugenekoloyesterday at 2:24 PM

But is it running ShellExecute on URIs?

show 1 reply