CVE-2022-23597:Element Desktop 的远程代码执行
hacktron.ai | 漏洞 | CVE-2022-23597 | #rce | #vulnerability-research | #sandbox-escape | #v8 | #electron | #cve-2022-23597 | #element-desktop
摘要
攻击者通过 iframe 注入、Electron 配置缺陷与 V8 漏洞利用的组合链,绕过沙箱并从子框架访问 Node.js API,实现对 Element Desktop 的完整 RCE。
- CVE
- CVE-2022-23597
- 发布时间
- 收录时间
Skip to content