Defense in depth — the Microsoft way (part 30): on exploitable Win32 functions

Posted by Stefan Kanthak on Mar 16

Hi @ll,

since Microsoft won’t — despite (hopefully not only) my constant
nagging and quite some bug reports about unquoted command lines
for more than a dozen years now — fix the BRAINDEAD behaviour
of Windows’ CreateProcess*() functions to play try&error instead
of returning on error to their caller when interpreting their
lpCommandLine argument which lets the BLOODY BEGINNER’s error
known as CWE-428 <…