΢Èí Edge ºÍ IE ä¯ÀÀÆ÷0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-01

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º
΢Èí Edge ºÍ IE ä¯ÀÀÆ÷


Îó²î¸ÅÊö


Ò»ÃûÑо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬ÓÉÓÚ΢Èíδ»Ø¸´×Ô¼ºÈÏÕæÈεÄ˽ÏÂÅû¶£¬£¬£¬£¬£¬Òò´Ë¾öÒé¹ûÕæÎ¢Èí Edge ºÍ IE ä¯ÀÀÆ÷ÖÐδÐÞ¸´µÄÁ½¸ö0dayÎó²îÏêÇéºÍ PoC¡£¡£¡£¡£¡£¡£¡£


ÕâÁ½¸öδÐÞ¸´µÄÎó²î£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÓ°Ïì΢Èí IE ä¯ÀÀÆ÷µÄ×îа汾£¬£¬£¬£¬£¬ÁíÍâÒ»¸öÓ°Ïì×îÐ嵀 Edge ä¯ÀÀÆ÷£¬£¬£¬£¬£¬ËüÃǾù¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÊܺ¦Õß web ä¯ÀÀÆ÷ÖеÄͬԴսÂÔ¡£¡£¡£¡£¡£¡£¡£


ͬԴսÂÔÊÇÏÖ´úä¯ÀÀÆ÷ÖÐʵÏÖµÄÒ»ÖÖÇå¾²¹¦Ð§£¬£¬£¬£¬£¬ÏÞÖÆÍ³Ò»¸öȪԴµÄÍøÒ³»ò¾ç±¾ºÍÁíÍâÒ»¸öȪԴµÄ×ÊÔ´¾ÙÐн»»¥£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹²»Ïà¹ØÕ¾µãÏ໥×ÌÈÅ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»»¾ä»°Ëµ£¬£¬£¬£¬£¬ÈôÊÇÓû§»á¼û web ä¯ÀÀÆ÷ÖеÄÕ¾µã£¬£¬£¬£¬£¬Ëü½ö¿ÉÇëÇó¼ÓÔØ¸ÃÕ¾µãµÄȪԴ£¨ÓòÃû£©ÖеÄÊý¾Ý£¬£¬£¬£¬£¬²»ÔÊÐí¸ÃÍøÕ¾ÒÔÓû§µÄÉí·ÝÌá³öÕë¶ÔÆäËüÍøÕ¾µÄδÊÚȨ»á¼û£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹ÆäÇÔÈ¡Óû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£


È»¶ø£¬£¬£¬£¬£¬ÕâÁ½¸ö0dayÎó²î£¬£¬£¬£¬£¬¿Éµ¼Ö¶ñÒâÍøÕ¾ÔÚÕë¶Ôͨ¹ýÒ×Êܹ¥»÷µÄÕâÁ½¸öÕ¾µã»á¼ûµÄí§ÒâÓòÃûʵÑéͨÓÿçÕ¾µã¾ç±¾£¨UXSS£©¹¥»÷¡£¡£¡£¡£¡£¡£¡£


ÒªÀÖ³ÉʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬¹¥»÷ÕßËùÐè×öµÄ¾ÍÊÇ˵·þÊܺ¦Õß·­¿ª¹¥»÷Õ߽ṹµÄ¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬´Óͳһä¯ÀÀÆ÷»á¼ûµÄÆäËüÕ¾µãÉÏÇÔÈ¡Êܺ¦ÕßÊý¾ÝÈçµÇ¼»á»°ºÍcookie¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâ±£´æÓÚ΢Èíä¯ÀÀÆ÷ÖÐµÄ Resource Timing Entries ÖУ¬£¬£¬£¬£¬Ëü²»×¼È·µØÔÚÖØ¶¨Ïòºó×ß©ÁË¿çÔ´ URL¡£¡£¡£¡£¡£¡£¡£


Îó²îʹÓÃ


ÏÖÔÚÒÑÐû²¼ÕâÁ½¸ö 0day Îó²îµÄ PoC£ºhttps://twitter.com/Windowsrcer/status/1111593640357355520¡£¡£¡£¡£¡£¡£¡£
Õë¶Ô IE µÄ PoC£ºpwning.click/iecrossurl.html
Õë¶Ô EdgeµÄ PoC: pwning.click/edgecrossurl.html


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÐÞ¸´½¨Òé


ÓÉÓÚÕâÁ½¸öÎó²îµÄÏêÇéºÍ PoC ÒÑÐû²¼£¬£¬£¬£¬£¬ºÚ¿ÍºÜ¿ì¾Í»áÕÒµ½Ê¹Ó÷½·¨´Ó¶ø¹¥»÷΢ÈíÓû§¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ΢ÈíûÓÐÐû²¼²¹¶¡¡£¡£¡£¡£¡£¡£¡£Óû§Ö»ÄÜÑ¡ÔñʹÓò»ÊÜÓ°ÏìµÄÆäËü web ä¯ÀÀÆ÷Èç Chrome »ò»ðºüä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html