

8·
2 days agoUser interaction required was listed on the MSRC source, but that’s also where “RCE” came from too.


User interaction required was listed on the MSRC source, but that’s also where “RCE” came from too.


Does anybody know of a resource that’s compiled known to be affected system or motherboard models using this specific BMC?
Eclypsium said the line of vulnerable AMI MegaRAC devices uses an interface known as Redfish. Server makers known to use these products include AMD, Ampere Computing, ASRock, ARM, Fujitsu, Gigabyte, Huawei, Nvidia, Supermicro, and Qualcomm. Some, but not all, of these vendors have released patches for their wares.
I don’t think it does. The MSRC page linking to the notepad update release notes/download goto the windows store version of notepad, which lists a requirement of Windows 11 version 22000.0 or higher.
I haven’t gone more in depth than that though.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841