΢Èí Edge ºÍ IE ä¯ÀÀÆ÷0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-01

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º
΢Èí Edge ºÍ IE ä¯ÀÀÆ÷


Îó²î¸ÅÊö


Ò»ÃûÑо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬ÓÉÓÚ΢Èíδ»Ø¸´×Ô¼ºÈÏÕæÈεÄ˽ÏÂÅû¶£¬£¬£¬£¬Òò´Ë¾öÒé¹ûÕæÎ¢Èí Edge ºÍ IE ä¯ÀÀÆ÷ÖÐδÐÞ¸´µÄÁ½¸ö0dayÎó²îÏêÇéºÍ PoC¡£¡£¡£¡£¡£¡£¡£


ÕâÁ½¸öδÐÞ¸´µÄÎó²î£¬£¬£¬£¬ÆäÖÐÒ»¸öÓ°Ïì΢Èí IE ä¯ÀÀÆ÷µÄ×îа汾£¬£¬£¬£¬ÁíÍâÒ»¸öÓ°Ïì×îÐ嵀 Edge ä¯ÀÀÆ÷£¬£¬£¬£¬ËüÃǾù¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÊܺ¦Õß web ä¯ÀÀÆ÷ÖеÄͬԴսÂÔ¡£¡£¡£¡£¡£¡£¡£


ͬԴսÂÔÊÇÏÖ´úä¯ÀÀÆ÷ÖÐʵÏÖµÄÒ»ÖÖÇå¾²¹¦Ð§£¬£¬£¬£¬ÏÞÖÆÍ³Ò»¸öȪԴµÄÍøÒ³»ò¾ç±¾ºÍÁíÍâÒ»¸öȪԴµÄ×ÊÔ´¾ÙÐн»»¥£¬£¬£¬£¬´Ó¶ø×èÖ¹²»Ïà¹ØÕ¾µãÏ໥×ÌÈÅ¡£¡£¡£¡£¡£¡£¡ £»£»£»£» £»£»£»»¾ä»°Ëµ£¬£¬£¬£¬ÈôÊÇÓû§»á¼û web ä¯ÀÀÆ÷ÖеÄÕ¾µã£¬£¬£¬£¬Ëü½ö¿ÉÇëÇó¼ÓÔØ¸ÃÕ¾µãµÄȪԴ£¨ÓòÃû£©ÖеÄÊý¾Ý£¬£¬£¬£¬²»ÔÊÐí¸ÃÍøÕ¾ÒÔÓû§µÄÉí·ÝÌá³öÕë¶ÔÆäËüÍøÕ¾µÄδÊÚȨ»á¼û£¬£¬£¬£¬´Ó¶ø×èÖ¹ÆäÇÔÈ¡Óû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£


È»¶ø£¬£¬£¬£¬ÕâÁ½¸ö0dayÎó²î£¬£¬£¬£¬¿Éµ¼Ö¶ñÒâÍøÕ¾ÔÚÕë¶Ôͨ¹ýÒ×Êܹ¥»÷µÄÕâÁ½¸öÕ¾µã»á¼ûµÄí§ÒâÓòÃûʵÑéͨÓÿçÕ¾µã¾ç±¾£¨UXSS£©¹¥»÷¡£¡£¡£¡£¡£¡£¡£


ÒªÀÖ³ÉʹÓÃÕâЩÎó²î£¬£¬£¬£¬¹¥»÷ÕßËùÐè×öµÄ¾ÍÊÇ˵·þÊܺ¦Õß·­¿ª¹¥»÷Õ߽ṹµÄ¶ñÒâÍøÕ¾£¬£¬£¬£¬´Óͳһä¯ÀÀÆ÷»á¼ûµÄÆäËüÕ¾µãÉÏÇÔÈ¡Êܺ¦ÕßÊý¾ÝÈçµÇ¼»á»°ºÍcookie¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâ±£´æÓÚ΢Èíä¯ÀÀÆ÷ÖÐµÄ Resource Timing Entries ÖУ¬£¬£¬£¬Ëü²»×¼È·µØÔÚÖØ¶¨Ïòºó×ß©ÁË¿çÔ´ URL¡£¡£¡£¡£¡£¡£¡£


Îó²îʹÓÃ


ÏÖÔÚÒÑÐû²¼ÕâÁ½¸ö 0day Îó²îµÄ PoC£ºhttps://twitter.com/Windowsrcer/status/1111593640357355520¡£¡£¡£¡£¡£¡£¡£
Õë¶Ô IE µÄ PoC£ºpwning.click/iecrossurl.html
Õë¶Ô EdgeµÄ PoC: pwning.click/edgecrossurl.html


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÐÞ¸´½¨Òé


ÓÉÓÚÕâÁ½¸öÎó²îµÄÏêÇéºÍ PoC ÒÑÐû²¼£¬£¬£¬£¬ºÚ¿ÍºÜ¿ì¾Í»áÕÒµ½Ê¹Ó÷½·¨´Ó¶ø¹¥»÷΢ÈíÓû§¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ΢ÈíûÓÐÐû²¼²¹¶¡¡£¡£¡£¡£¡£¡£¡£Óû§Ö»ÄÜÑ¡ÔñʹÓò»ÊÜÓ°ÏìµÄÆäËü web ä¯ÀÀÆ÷Èç Chrome »ò»ðºüä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html