security1 publisher
Microsoft's DebugMCP 1.1.4 left an unauthenticated debugger port open to malicious webpages
Imperva found Microsoft's DebugMCP 1.1.4 let a malicious webpage run code on a developer's machine through an unauthenticated port 3001 listener. The fix reached 1.2.0 with no advisory, so finding exposed machines means checking installed extension versions.
Publishers:imperva.com
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60