Flash Broker-Based Sandbox Escape Via Timing Attack Against File Moving

Discussion in 'News Aggregator' started by Packet Storm, 20 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    FlashBroker is vulnerable to NTFS junction attack to write an arbitrary file to the filesystem under user permissions. There is a race condition in FlashBroker BrokerMoveFileEx method. This race can be won by using an oplock to wait for the point where the BrokerMoveFileEx method opens the original file and then making destination to be a junction.

    Continue reading...
     

Share This Page

Loading...