CL.0 desync in www.microsoft.c... Note

CL.0 desync in www.microsoft.com

Posted by shed riot on Aug 06# Summary I reported the issue to the Microsoft Security Response Center twice: * VULN-165381, MSRC case 102964 * VULN-165876, MSRC case 103259 In both cases, they do not appear to have even looked at the PoCs, and so have failed to adequately investigate before reaching a decision. # Vulnerability CWE-444: HTTP Request/Response Smuggling The observed behaviour was consistent with CL.0 HTTP desync within the request-processing chain. #...