΢Èí Edge ºÍ IE ä¯ÀÀÆ÷0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-04-01Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
΢Èí Edge ºÍ IE ä¯ÀÀÆ÷
Îó²î¸ÅÊö
Ò»ÃûÑо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬ÓÉÓÚ΢Èíδ»Ø¸´×Ô¼ºÈÏÕæÈεÄ˽ÏÂÅû¶£¬£¬£¬£¬£¬Òò´Ë¾öÒé¹ûÕæÎ¢Èí Edge ºÍ IE ä¯ÀÀÆ÷ÖÐδÐÞ¸´µÄÁ½¸ö0dayÎó²îÏêÇéºÍ PoC¡£¡£¡£¡£
ÕâÁ½¸öδÐÞ¸´µÄÎó²î£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÓ°Ïì΢Èí IE ä¯ÀÀÆ÷µÄ×îа汾£¬£¬£¬£¬£¬ÁíÍâÒ»¸öÓ°Ïì×îÐ嵀 Edge ä¯ÀÀÆ÷£¬£¬£¬£¬£¬ËüÃǾù¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÊܺ¦Õß web ä¯ÀÀÆ÷ÖеÄͬԴսÂÔ¡£¡£¡£¡£
ͬԴսÂÔÊÇÏÖ´úä¯ÀÀÆ÷ÖÐʵÏÖµÄÒ»ÖÖÇå¾²¹¦Ð§£¬£¬£¬£¬£¬ÏÞÖÆÍ³Ò»¸öȪԴµÄÍøÒ³»ò¾ç±¾ºÍÁíÍâÒ»¸öȪԴµÄ×ÊÔ´¾ÙÐн»»¥£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹²»Ïà¹ØÕ¾µãÏ໥×ÌÈÅ¡£¡£¡£¡£»£»£»»¾ä»°Ëµ£¬£¬£¬£¬£¬ÈôÊÇÓû§»á¼û web ä¯ÀÀÆ÷ÖеÄÕ¾µã£¬£¬£¬£¬£¬Ëü½ö¿ÉÇëÇó¼ÓÔØ¸ÃÕ¾µãµÄȪԴ£¨ÓòÃû£©ÖеÄÊý¾Ý£¬£¬£¬£¬£¬²»ÔÊÐí¸ÃÍøÕ¾ÒÔÓû§µÄÉí·ÝÌá³öÕë¶ÔÆäËüÍøÕ¾µÄδÊÚȨ»á¼û£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹ÆäÇÔÈ¡Óû§Êý¾Ý¡£¡£¡£¡£
È»¶ø£¬£¬£¬£¬£¬ÕâÁ½¸ö0dayÎó²î£¬£¬£¬£¬£¬¿Éµ¼Ö¶ñÒâÍøÕ¾ÔÚÕë¶Ôͨ¹ýÒ×Êܹ¥»÷µÄÕâÁ½¸öÕ¾µã»á¼ûµÄí§ÒâÓòÃûʵÑéͨÓÿçÕ¾µã¾ç±¾£¨UXSS£©¹¥»÷¡£¡£¡£¡£
ÒªÀÖ³ÉʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬¹¥»÷ÕßËùÐè×öµÄ¾ÍÊÇ˵·þÊܺ¦Õß·¿ª¹¥»÷Õ߽ṹµÄ¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬´Óͳһä¯ÀÀÆ÷»á¼ûµÄÆäËüÕ¾µãÉÏÇÔÈ¡Êܺ¦ÕßÊý¾ÝÈçµÇ¼»á»°ºÍcookie¡£¡£¡£¡£¸ÃÎÊÌâ±£´æÓÚ΢Èíä¯ÀÀÆ÷ÖÐµÄ Resource Timing Entries ÖУ¬£¬£¬£¬£¬Ëü²»×¼È·µØÔÚÖØ¶¨Ïòºó×ß©ÁË¿çÔ´ URL¡£¡£¡£¡£
Îó²îʹÓÃ
ÏÖÔÚÒÑÐû²¼ÕâÁ½¸ö 0day Îó²îµÄ PoC£ºhttps://twitter.com/Windowsrcer/status/1111593640357355520¡£¡£¡£¡£
Õë¶Ô IE µÄ PoC£ºpwning.click/iecrossurl.html
Õë¶Ô EdgeµÄ PoC: pwning.click/edgecrossurl.html
ÐÞ¸´½¨Òé
ÓÉÓÚÕâÁ½¸öÎó²îµÄÏêÇéºÍ PoC ÒÑÐû²¼£¬£¬£¬£¬£¬ºÚ¿ÍºÜ¿ì¾Í»áÕÒµ½Ê¹Ó÷½·¨´Ó¶ø¹¥»÷΢ÈíÓû§¡£¡£¡£¡£
ÏÖÔÚ΢ÈíûÓÐÐû²¼²¹¶¡¡£¡£¡£¡£Óû§Ö»ÄÜÑ¡ÔñʹÓò»ÊÜÓ°ÏìµÄÆäËü web ä¯ÀÀÆ÷Èç Chrome »ò»ðºüä¯ÀÀÆ÷¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html