不该发生的点击:Internet Explorer 中的点击劫持 RCE
swarm.ptsecurity.com | 研究 | #rce | #windows | #clickjacking | #internet-explorer | #webbrowser-control | #activex
摘要
尽管 Internet Explorer 已于 2020 年终结支持,其引擎仍以 WebBrowser 控件形式广泛用于 VB/.NET/C# 应用。PT SWARM 按严重程度升序披露了此类软件中的多个漏洞,并最终展示通过点击劫持实现远程代码执行(RCE)的攻击链。
- 发布时间
- 收录时间
Skip to content