FF Sandbox Escape (CVE-2020-12388)
projectzero.google | vulnerability | CVE-2020-12388 | #rce | #firefox | #sandbox-escape | #windows | #cve | #project-zero
Summary
By James Forshaw, Project Zero In my previous blog post I discussed an issue with the Windows Kernel’s handling of Restricted Tokens which allowed me to escape the Chrome GPU sandbox. Originally I’d planned to use Firefox for the proof-of-concept as Firefox uses the same effective sandbox level as the Chrome GPU process for its content renderers. That means a FF content RCE would give code execution in a sandbox where you could abuse the Windows Kernel Restricted Tokens issue, making it much more serious.
- CVE
- CVE-2020-12388
- Published
- Collected
Skip to content