IE8 Successfully Exploited on Windows 7 64bit

Soldato
Joined
7 Apr 2004
Posts
4,212
Just thought this was worth posting here, as IE8 is very highly regarded for its security. It was successfully exploited, bypassing both ASLR & DEP at the Pwn2Own contest.

There has been a couple of successful attacks against these protections in the past year but considering how robust they have been, this is quite significant IMO. Will no doubt have some more holes punched in it shortly with better standardized exploitation techniques/research appearing.

Exploit paper detailing techniques is here for anyone interested, very interesting bypass of DEP, http://vreugdenhilresearch.nl/Pwn2Own-2010-Windows7-InternetExplorer8.pdf

Been a bad week for browsers across the board :p
 
UAC not enabled however, which meant no IE Protected mode.

Hmm yer that's a good point, there is no mention of attacking protected mode. Still though, even a successful non-persistent exploit restricted to protected mode could do a fair bit of damage under the correct circumstances.
 
Back
Top Bottom