This CHT Posted November 4, 2022 Share Posted November 4, 2022 Inject into IE11. Will work on other sandboxes that allow the opening of windows filepickers through a broker. You will gain medium IL javascript execution, at which point you simply retrigger your IE RCE bug. EDB Note ~ Download: https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/46919.zip Link to post Link to comment Share on other sites More sharing options...
Recommended Posts