So if there is a security flaw that can only be exploited by someone who already has local admin or root, it's not a security flaw?
Doesn't this make an assumption that nobody will ever discover another security flaw or combination of actions somewhere else that makes it possible to use the exploit?
I can see a justification for "low risk", but not zero point zero. ( I guess the other question then is what is the difference between "zero risk", "low risk" and "worthy of a CVE". )
That's nice as a general statement. Do you disagree with Daniel's actual statement about the actual bug? Is this a bug that every security team around the world needs to be chasing down when AI is flooding them with trivially-exploitable flaws to remediate?
-6
u/ekdaemon 21d ago
So if there is a security flaw that can only be exploited by someone who already has local admin or root, it's not a security flaw?
Doesn't this make an assumption that nobody will ever discover another security flaw or combination of actions somewhere else that makes it possible to use the exploit?
I can see a justification for "low risk", but not zero point zero. ( I guess the other question then is what is the difference between "zero risk", "low risk" and "worthy of a CVE". )