The software defects, which have a maximum-severity rating, do not require authentication and allow remote attackers to execute code arbitrarily on the underlying system.
Trend Micro researchers discovered and reported the eight-year-old defect to Microsoft six months ago. The company hasn’t made any commitments to patch or remediate the issue.
Richard Zhu, left, and Amat Cama celebrate one of their successes on the first day of the 2019 Pwn2Own competition in Vancouver. (Zero Day Initiative / YouTube)
The hacker competition added an automotive category for its upcoming event in Vancouver, with the full blessing of the car company. One winning researcher will be able…