republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
348
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC
kudos:7

Advanced Exploitation IE MSXML Remote Uninitialized Memory

(MS12-043 / CVE-2012-1889)

Published on 2012-07-17 17:08:46 UTC by Nicolas Joly, Security Researcher @ VUPEN

Hi exploiters,

A few weeks ago, criminals decided to offer to the security community a new in-the-wild zero-day exploit affecting Microsoft Windows XML Core Services, known as CVE-2012-1889 and patched as part of the MS12-043 security bulletin. While the nature of the flaw and its exploitability using Internet Explorer with a non-ASLRed Java6 plug-in have been largely discussed over the web, no advanced methods have been publicly documented to exploit the flaw on Windows 7 and bypass ASLR/DEP without using any third-party plug-in.

The aim of this blog post is to share the methods we have found and used to get a memory leak from this specific bug, and prove that ASLR and DEP can be circumvented without the need of a third-party module such as JRE6.

1. Technical Analysis of the Vulnerability

This specific vulnerability can be triggered by a single JavaScript line that should be enough to crash any unpatched IE version:

»www.vupen.com/blog/20120717.Adva···-043.php
--
Gladiator Security Forum
»www.gladiator-antivirus.com/

Wednesday, 19-Jun 08:41:40 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics