Hoşgeldin Misafir

Microsoft Windows VCF or Contact File - URL Manipulation-Spoof Arbitrary Code Executi

SurHan

28 Kas 2017
4,186 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
# Exploit Title:  Microsoft Windows 'VCF' or 'Contact' File URL Manipulation-Spoof Arbitrary Code Execution Vulnerability -- Remote Vector
 
# Exploit Author:  Eduardo Braun Prado
 
# Vendor Homepage: http://www.microsoft.com/
 
# Software Link: http://www.microsoft.com/
 
# Version: Windows 7 SP1, 8.1, 10 v.1809 with full patches up to January 2019. both x86 and x64 architectures.
 
# Tested on: Windows 7 SP1, 8.1, 10 v.1809 with full patches up to January 2019. both x86 and x64 architectures.
 
# CVE : n/a
 
 
Proof of Concept:
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/46220.zip
 
#  0day.today [2019-01-22]  #