
Critical Flaw Found in Microsoft's New NLWeb Protocol
A critical vulnerability allowing remote access to sensitive files, including API keys, has been discovered in Microsoft's new NLWeb protocol. Researchers Aonan Guan and Lei Wang reported the flaw in May, with Microsoft patching it in July but not issuing a CVE. The vulnerability, a classic path traversal flaw,...








