΢Èí Edge ºÍ IE ä¯ÀÀÆ÷0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-04-01·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
΢Èí Edge ºÍ IE ä¯ÀÀÆ÷
·ì϶¸ÅÊö
Ò»Ãû×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬ÓÉÓÚ΢Èíδ»Ø¸´×Ô¼ºÕƹÜÈεݵÀïÅû¶£¬£¬£¬£¬£¬£¬Òò¶ø¾ö¶¨¹«¿ªÎ¢Èí Edge ºÍ IE ä¯ÀÀÆ÷ÖÐ佨¸´µÄÁ½¸ö0day·ì϶ÏêÇéºÍ PoC¡£¡£¡£¡£¡£
ÕâÁ½¸ö佨¸´µÄ·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÓ°Ïì΢Èí IE ä¯ÀÀÆ÷µÄ×îа汾£¬£¬£¬£¬£¬£¬Áí±íÒ»¸öÓ°Ïì×îÐ嵀 Edge ä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬ËüÃǾù¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÊܺ¦Õß web ä¯ÀÀÆ÷ÖеÄͬԴսÊõ¡£¡£¡£¡£¡£
ͬԴսÊõÊÇÏÖ´úä¯ÀÀÆ÷ÖÐʵÏÖµÄÒ»ÖÖ°²È«Ö°ÄÜ£¬£¬£¬£¬£¬£¬ÏÞ¶Èͳһ¸öÆðÔ´µÄÍøÒ³»ò¾ç±¾ºÍÁí±íÒ»¸öÆðÔ´µÄ×ÊÔ´½øÐн»»¥£¬£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹²»ÓйØÕ¾µã»¥ÓйØÈÅ¡£¡£¡£¡£¡£»£»£»£»£»£»£»»¾ä»°Ëµ£¬£¬£¬£¬£¬£¬ÈôÊÇÓû§½Ó¼û web ä¯ÀÀÆ÷ÖеÄÕ¾µã£¬£¬£¬£¬£¬£¬Ëü½ö¿ÉÒªÇó¼ÓÔØ¸ÃÕ¾µãµÄÆðÔ´£¨ÓòÃû£©ÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬²»ÔÊÐí¸ÃÍøÕ¾ÒÔÓû§µÄÉí·ÝÌá³öÕë¶ÔÆäËüÍøÕ¾µÄδÊÚȨ½Ó¼û£¬£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹ÆäÇÔÈ¡Óû§Êý¾Ý¡£¡£¡£¡£¡£
È»¶ø£¬£¬£¬£¬£¬£¬ÕâÁ½¸ö0day·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¶ñÒâÍøÕ¾ÔÚÕë¶Ôͨ¹ýÒ×Êܹ¥»÷µÄÕâÁ½¸öÕ¾µã½Ó¼ûµÄËÁÒâÓòÃûÖ´ÐÐͨÓÿçÕ¾µã¾ç±¾£¨UXSS£©¹¥»÷¡£¡£¡£¡£¡£
Òª³É¹¦ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßËùÐè×öµÄ¾ÍÊÇ˵·þÊܺ¦Õß´ò¿ª¹¥»÷Õß»ú¹ØµÄ¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬´Óͳһä¯ÀÀÆ÷½Ó¼ûµÄÆäËüÕ¾µãÉÏÇÔÈ¡Êܺ¦ÕßÊý¾ÝÈçµÇ¼»á»°ºÍcookie¡£¡£¡£¡£¡£¸ÃÎÊÌâ´æÔÚÓÚ΢Èíä¯ÀÀÆ÷ÖÐµÄ Resource Timing Entries ÖУ¬£¬£¬£¬£¬£¬Ëü²»ÕýÈ·µØÔÚ³Á¶¨Ïòºóй©ÁË¿çÔ´ URL¡£¡£¡£¡£¡£
·ì϶ÀûÓÃ
ĿǰÒѰ䲼ÕâÁ½¸ö 0day ·ì϶µÄ PoC£ºhttps://twitter.com/Windowsrcer/status/1111593640357355520¡£¡£¡£¡£¡£
Õë¶Ô IE µÄ PoC£ºpwning.click/iecrossurl.html
Õë¶Ô EdgeµÄ PoC: pwning.click/edgecrossurl.html
½¨¸´½¨Òé
ÓÉÓÚÕâÁ½¸ö·ì϶µÄÏêÇéºÍ PoC ÒѰ䲼£¬£¬£¬£¬£¬£¬ºÚ¿ÍºÜ¿ì¾Í»áÕÒµ½ÀûÓ÷½Ê½´Ó¶ø¹¥»÷΢ÈíÓû§¡£¡£¡£¡£¡£
Ŀǰ΢ÈíûÓа䲼²¹¶¡¡£¡£¡£¡£¡£Óû§Ö»ÄÜÑ¡ÔñʹÓò»ÊÜÓ°ÏìµÄÆäËü web ä¯ÀÀÆ÷Èç Chrome »ò»ðºüä¯ÀÀÆ÷¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html


¾©¹«Íø°²±¸11010802024551ºÅ