CL.0 desync in www.microsoft.com
Posted by shed riot on Aug 06# Summary I reported the issue to the Microsoft Security Response Center twice: * VULN-165381, MSRC case 102964
* VULN-165876, MSRC case 103259 In both cases, they do not appear to have even looked at the PoCs, and so
have failed to adequately investigate before reaching a decision. # Vulnerability CWE-444: HTTP Request/Response Smuggling The observed behaviour was consistent with CL.0 HTTP desync within the
request-processing chain. #...