Hacker News new | ask | show | jobs
by jeroenhd 275 days ago
.scr files are untrusted because they're plain PE executables. You don't need to exploit anything to get code execution because all they do is execute code.

If they were just video files, they wouldn't be such a vector for malware.

1 comments

You still need to priv esc