2026-04-24 01:55 UTC
This is why CVE scoring is used for severity. A vuln that doesn't really give you anything, that you can only exploit locally, when already having elevated privileges? That's going to be low priority for a fix.
Replies (1)
-
@MangoCats@feddit.it 2026-04-24 02:16
> A vuln that doesn’t really give you anything, that you can only exploit locally, when already having elevated privileges? That’s going to be low priority for a fix. And, yet, here I am - rebuilding a new interim image for our security team to scan so they can generate a spreadsheet with hundreds of lines of "items of concern" which are above our "threshold of concern" and most of them are being dismissed because of those justifications you just gave: local exploit only, etc. but I have to read every one, tease out the "local exploit only" language, quote it for the justification, over and over and over every few months. Corporate anxiety is limitless.