PoC Code Available for Microsoft Edge Remote Code Execution Bug

Discussion in 'other security issues & news' started by guest, Oct 12, 2018.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Find the guy a job and he will owe you ……….. Hopefully he will find one before the "Dark Side" uses his talents.
    https://twitter.com/Yux1xi
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Wait a minute, say what? So it didn't stop it from executing calc.exe? That's why anti-exe is still one the best solutions against exploits. Same goes for third party sandboxes, if Edge was protected with SBIE ithe malware would have been contained. But Edge can't be sandboxed of course.
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    yes
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Now that I think of it, this exploit is not based on memory corruption, so probably that's why MBAE didn't stop it. I'm guessing that HMPA will also not stop it.
     
  5. guest

    guest Guest

    Demo Exploit Code Published for Remote Code Execution via Microsoft Edge
    December 27, 2018
    https://www.bleepingcomputer.com/ne...for-remote-code-execution-via-microsoft-edge/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.