Exploiting MS16-145: MS Edge TypedArray.sort Use-After-Free (CVE-2016-7288)
blog.quarkslab.com | vulnerability | CVE-2016-7288 | #rce | #use-after-free | #windows | #exploitation | #cve | #microsoft-edge | #control-flow-guard
Summary
Exploiting CVE-2016-7288, a use-after-free in MS Edge's TypedArray.sort: root cause analysis, reliable triggering, abusing Quicksort and WebGL for read/write primitives, and a CFG bypass with COOP.
- Published
- Collected
Skip to content