
Tribell Edge Sandbox Escape - PoCs of Edge's legacy vulnerabilities BadgeUpdateManager / TileFlyoutUpdateManager / ToastNotificationManager to exploit cross-boundary XmlDocument sharing and escape Edge’s LPAC sandbox (CVE-2019-0555).
Tribell Edge Sandbox Escape - PoCs of Edge's legacy vulnerabilities BadgeUpdateManager / TileFlyoutUpdateManager / ToastNotificationManager to exploit cross-boundary XmlDocument sharing and escape Edge’s LPAC sandbox (CVE-2019-0555).
The PoCs trigger the execution of notepad.exe within the Just-In-Time (JIT) compilation process.
A number of Partial Trust Windows Runtime classes expose the XmlDocument class across process boundaries to less privileged callers, which in its original form could be abused to elevate privileges and escape the Edge Content LPAC sandbox.
This PoC uses BadgeUpdateManager, TileFlyoutUpdateManager, and ToastNotificationManager to reproduce the cross-boundary exposure and achieve sandbox escape. The vulnerability has been patched by Microsoft and no longer works on fully updated systems.
XmlDocumentWhile developing the exploit code, wrote and compiled the following C++ code to investigate how each class is used, and then examined GUID values and offsets in IDA.
...
ComPtr<ITileFlyoutUpdateManagerStatics> manager;
HStringReference name(RuntimeClass_Windows_UI_Notifications_TileFlyoutUpdateManager);
Check(RoGetActivationFactory(name.Get(), IID_PPV_ARGS(&manager)));
ComPtr<IXmlDocument> doc;
Check(manager->GetTemplateContent(TileFlyoutTemplateType::TileFlyoutTemplateType_TileFlyoutTemplate01, doc.GetAddressOf()));
ComPtr<IXMLDOMDocument2> dom;
Check(doc.As(&dom));
...