Exploit Development: Browser Exploitation on Windows - CVE-2019-0567, A Microsoft Edge Type Confusion Vulnerability (Part 2)
ID: 12aa8f33-d1af-5eba-a838-0c38a93620d4
STIX ID: report--12aa8f33-d1af-5eba-a838-0c38a93620d4
Feed Name: Connor McGarr’s Blog
This is a detailed exploitation walkthrough for CVE-2019-0567 in ChakraCore/Edge that progresses from a type-confusion crash to a reliable arbitrary read/write primitive, ASLR and DEP bypasses, leaking module and stack addresses, and constructing a ROP chain to achieve remote code execution (demonstrated by launching calc.exe). It documents debugging steps, object layout analysis, DataView-based memory primitives, and pragmatic techniques to defeat Control Flow Guard by overwriting return addresses on the stack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
