• bizdelnick@lemmy.ml
    link
    fedilink
    arrow-up
    26
    ·
    edit-2
    2 years ago

    I wonder if Matt calculated CVSS score before calling this vulnerability “critical”.

    • folkrav@lemmy.ca
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      2 years ago

      It’s the last sentence of the article - 9.8/10. In this case it’s probably called critical because of the potential consequences of the exploit being a full machine takeover, not the likeliness of the exploit being used.

      • bizdelnick@lemmy.ml
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        2 years ago

        It means that CVSS is calculated wrong. It can’t be so big because default configuration is not affected and attacker requires admin access to change it.