❌

Normal view

Received β€” 21 January 2026 ⏭ /r/netsec - Information Security News & Discussion

WinBoat: Drive by Client RCE + Sandbox escape.

Winboat lets you "Run Windows apps on 🐧 Linux with ✨ seamless integration"

I chained together an unauthenticated file upload to an "update" route and a command injection in the host election app to active full "drive by" host takeover in winboat.

submitted by /u/reddit4matt
[link] [comments]
❌