
microsoft turned me down
Keywords
Summary
122 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable technical insights into a real-world vulnerability and its variant. The argumentation is solid, based on hands-on demonstrations and code analysis. The author clearly explains the attack chain and the reasoning behind Microsoft’s decision, though he disagrees with it. The value lies in the practical demonstration and the discussion of vulnerability disclosure processes.
Scientific Rigor, Source Quality, Title Accuracy
The video cites the Check Point research and the Microsoft CVE page, which are authoritative sources. The title is somewhat clickbait but accurately reflects the content. The technical rigor is high, with clear explanations and reproducible steps. The author’s personal experience with MSRC adds credibility, though the rejection is based on Microsoft’s criteria.
124 words
Title / Content Match
The title is catchy and reflects the narrative of the video, which focuses on the author's experience reporting a vulnerability to Microsoft and being rejected.
Quality & Reliability
8/10
The video provides a detailed technical demonstration of a vulnerability, referencing a specific CVE and research from Check Point. The methodology is transparent, and the author's expertise is evident. However, the content is based on personal testing and opinion, with limited external verification.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction to CVE-2025-33053 and the Check Point research
- Analysis of the .url file and iediagcmd.exe
- Demonstration of the .url attack in a virtual machine
- Testing the .lnk variant and finding it still works
- Reporting the vulnerability to Microsoft MSRC
- Microsoft's rejection and the author's reaction
- Discussion of the implications and final thoughts
Cited Sources
- Stealth Falcon and Horus: A Saga of Middle Eastern Cyber Espionage — Check Point Research article detailing the vulnerability and attack chain
- CVE-2025-33053 - Internet Shortcut Files Remote Code Execution Vulnerability — Microsoft Security Response Center page for the CVE
Concurring Sources
- Check Point Research — The original research on CVE-2025-33053
Dissenting Sources
- Microsoft's response — Microsoft considered the .url variant a vulnerability but rejected the .lnk variant as requiring social engineering.
External References
Contribution & Novelties
The video provides a novel demonstration that the .lnk variant of the vulnerability remains unpatched, highlighting a potential gap in Microsoft’s patching. It also offers a detailed walkthrough of the vulnerability discovery and reporting process, which is educational for security researchers.
Pour aller plus loin :
- Windows Shortcut (.lnk) files — Background on .lnk files.
- WebDAV — Protocol used for remote file access.
- MSRC Vulnerability Reporting — Microsoft’s vulnerability reporting process.
71 words
Radar Profile
The radar profile shows high scores in technical level and information quality, reflecting the detailed technical demonstration and solid research. The fiabilite_globale is slightly lower due to the reliance on personal testing and the controversial nature of the vulnerability classification.
💬 Sur les 30 commentaires analysés, le climat est très positif, avec une majorité de spectateurs soutenant l'auteur et critiquant la décision de Microsoft. Les commentaires expriment une ferveur pour la démonstration technique et une frustration partagée envers le processus de divulgation de Microsoft.