利用 MS16-145:MS Edge TypedArray.sort 释放后使用(CVE-2016-7288)
blog.quarkslab.com | 漏洞 | CVE-2016-7288 | #rce | #use-after-free | #windows | #exploitation | #cve | #microsoft-edge | #control-flow-guard
摘要
完整剖析并利用 MS Edge TypedArray.sort 释放后使用漏洞(CVE-2016-7288):从根因与稳定触发,到操纵 Quicksort、借 WebGL 构造读写原语,最终以 COOP 绕过 Control Flow Guard。
- 发布时间
- 收录时间
Skip to content