Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

FF Sandbox Escape (CVE-2020-12388)

Summary

By James Forshaw, Project Zero In my previous blog post I discussed an issue with the Windows Kernel’s handling of Restricted Tokens which allowed me to escape the Chrome GPU sandbox. Originally I’d planned to use Firefox for the proof-of-concept as Firefox uses the same effective sandbox level as the Chrome GPU process for its content renderers. That means a FF content RCE would give code execution in a sandbox where you could abuse the Windows Kernel Restricted Tokens issue, making it much more serious.
CVE
CVE-2020-12388
Published
Collected

original ↗