…“The vulnerable driver ships with every version of Windows, up to and including Server 2025,” Adam Barnett, lead software engineer at Rapid7, said. “Maybe your fax modem uses a different chipset, and so you don’t need the Agere driver? Perhaps you’ve simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator.”…

  • FreedomAdvocate@lemmy.net.au
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    19 hours ago

    Fixed and required physical access to the machine. If someone malicious has physical access to your machine you’re already done.

    • utopiah@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      11 hours ago

      Does it mean you don’t think login password with physical token with disk encryption work?

        • utopiah@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          Thanks for clarifying, guess you meant “required physical access to the machine AND being logged in.” then which makes a huge difference.