Defense in depth -- the Micros... Note

Defense in depth -- the Microsoft way (part 94): BACKDOOR planted in AppLocker

Posted by Stefan Kanthak via Fulldisclosure on Sep 22Hi @ll, since several years Microsoft installs the DLLs domain_actions.dll and well_known_domains.dll as part of their Edge browser as well as Windows' WebView component into each and every user profile, UNPROTECTED against tampering. On Windows 11 24H2 their paths are currently "%LOCALAPPDATA%\Microsoft\Edge\User Data\Domain Actions\3.0.0.16\domain_actions.dll" "%LOCALAPPDATA%\Microsoft\Edge\User Data\Domain...