
Yuki Chen
@guhe120
古河, Indepent security researcher, Bug bounty, ACG Otaku, Pwn2Own 15/16/17, PwnFest16,TianfuCup 18/19/20, 5 times MSRC MVR yearly Top 1. Got two pwnie awards.
ID: 1916213911
29-09-2013 04:58:00
371 Tweet
10,10K Followers
280 Following








Hello Security Response, is there any legitimate process inside MSRC to escalate an issue if I beleive it's not assessed properly and fairly by current engineering team?


Nice analysis but it seems this PoC is an information leak bug (CVE-2024-49113 ?) I reported that is incorrectly tagged as DoS. So instead of calling it LDAPNightmare I'd prefer LdapBleeding. And Security Response could you please help to correct the bulletin🤣?






My great honor to be selected as an Off-By-One Conference speaker, let's reveal some interesting bugs under that mysterious AcceptSecuirtyContext API #OBO2025


