Microsoft Edge File Permissions Clash with IE, Allow XXE Attacks

Mohammad.Poorya

Bardzo aktywny
Ekspert
Dołączył
19 Wrzesień 2018
Posty
3209
Reakcje/Polubienia
12998
Miasto
On a Bike!
A recently disclosed vulnerability affecting Internet Explorer, yet to receive a fix from Microsoft, has received a micropatch that denies remote attackers the possibility to exfiltrate local files and run reconnaissance activity on the system.

An XML External Entity (XXE), the security flaw was discovered and reported on March 27 to Microsoft by security researcher
Zaloguj lub Zarejestruj się aby zobaczyć!
. He
Zaloguj lub Zarejestruj się aby zobaczyć!
the details on April 10, including proof-of-concept code to support his finding.

The researcher also published a video showing how the vulnerability can be exploited:
Zaloguj lub Zarejestruj się aby zobaczyć!
 
Do góry