microsoft turned me down

microsoft turned me down

🎙 John Hammond 👥 2.2M 📅 November 13, 2025 ⏱ 37 min 👁 61K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

CVE-2025-33053LNKURLWebDAVMSRC

Summary

In this video, John Hammond explores CVE-2025-33053, a vulnerability in Windows Internet Shortcut files (.url) that allows remote code execution via a crafted shortcut pointing to a WebDAV server. He demonstrates the attack using a .url file that invokes iediagcmd.exe, which then executes an attacker-controlled executable from a remote location. He then investigates whether the same technique works with .lnk files (Windows shortcuts) and finds that it does, even after the .url vulnerability was patched. He reports this to Microsoft’s MSRC, but they reject the report, stating that the .lnk variant requires social engineering and is not considered a vulnerability. The video provides a detailed walkthrough of the technical process, including static and dynamic analysis, and discusses the implications of Microsoft’s decision.

122 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable technical insights into a real-world vulnerability and its variant. The argumentation is solid, based on hands-on demonstrations and code analysis. The author clearly explains the attack chain and the reasoning behind Microsoft’s decision, though he disagrees with it. The value lies in the practical demonstration and the discussion of vulnerability disclosure processes.

Scientific Rigor, Source Quality, Title Accuracy

The video cites the Check Point research and the Microsoft CVE page, which are authoritative sources. The title is somewhat clickbait but accurately reflects the content. The technical rigor is high, with clear explanations and reproducible steps. The author’s personal experience with MSRC adds credibility, though the rejection is based on Microsoft’s criteria.

124 words

Title / Content Match

The title is catchy and reflects the narrative of the video, which focuses on the author's experience reporting a vulnerability to Microsoft and being rejected.

Quality & Reliability

8/10

The video provides a detailed technical demonstration of a vulnerability, referencing a specific CVE and research from Check Point. The methodology is transparent, and the author's expertise is evident. However, the content is based on personal testing and opinion, with limited external verification.

Key Moments

Cited Sources

Concurring Sources

Dissenting Sources

  • Microsoft's response — Microsoft considered the .url variant a vulnerability but rejected the .lnk variant as requiring social engineering.

External References

Contribution & Novelties

The video provides a novel demonstration that the .lnk variant of the vulnerability remains unpatched, highlighting a potential gap in Microsoft’s patching. It also offers a detailed walkthrough of the vulnerability discovery and reporting process, which is educational for security researchers.

Pour aller plus loin :

71 words

Radar Profile

The radar profile shows high scores in technical level and information quality, reflecting the detailed technical demonstration and solid research. The fiabilite_globale is slightly lower due to the reliance on personal testing and the controversial nature of the vulnerability classification.

Reliability 7/10

💬 Sur les 30 commentaires analysés, le climat est très positif, avec une majorité de spectateurs soutenant l'auteur et critiquant la décision de Microsoft. Les commentaires expriment une ferveur pour la démonstration technique et une frustration partagée envers le processus de divulgation de Microsoft.