Lucene search

K
canvasImmunity CanvasIE_CARDSPACECLAIMCOLLECTION
HistoryNov 12, 2013 - 2:35 p.m.

Immunity Canvas: IE_CARDSPACECLAIMCOLLECTION

2013-11-1214:35:00
Immunity Canvas
exploitlist.immunityinc.com
28

0.963 High

EPSS

Percentile

99.6%

Name ie_cardspaceclaimcollection
CVE CVE-2013-3918 Exploit Pack
VENDOR: Microsoft
NOTES:
- This exploits leaks a vtable pointer of a CTable object in order to bypass ASLR
- We also leak the shellcode’s address so there’s no need for heap spraying

This exploit has been tested on:
- Windows 7 Professional (x86) on IE 9 mshtml.dll version 9.00.8112.16457.
- Windows 7 Home Basic (x64) on IE 9 32 bits mshtml.dll version 9.00.8112.16421.
- Windows 7 Ultimate (x86) on IE 8 mshtml.dll version 8.00.7600.16385.

Repeatability: Single
References: http://technet.microsoft.com/en-us/security/bulletin/ms13-090
CVE Url: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3918