Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2015-6086 — CVE-2015-6086 的 PoC | Kitploit
工具/GitHubGitHub/payatu/cve-2015-6086
漏洞分析漏洞利用Web应用程序漏洞利用学习与教育二进制利用实验室与实践
GitHubpayatu/cve-2015-6086

CVE-2015-6086

CVE-2015-6086 的 PoC

查看仓库
673210年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

从崩溃到利用:CVE-2015-6086 - 越界读取/ASLR 绕过

===================================================================

root@kitploit:~
 $$$$$$\  $$\    $$\ $$$$$$$$\       $$$$$$\   $$$$$$\    $$\  $$$$$$$\          $$$$$$\   $$$$$$\   $$$$$$\
$$  __$$\ $$ |   $$ |$$  _____|     $$  __$$\ $$$ __$$\ $$$$ | $$  ____|        $$  __$$\ $$$ __$$\ $$  __$$\
$$ /  \__|$$ |   $$ |$$ |           \__/  $$ |$$$$\ $$ |\_$$ | $$ |             $$ /  \__|$$$$\ $$ |$$ /  $$ |
$$ |      \$$\  $$  |$$$$$\ $$$$$$\  $$$$$$  |$$\$$\$$ |  $$ | $$$$$$$\ $$$$$$\ $$$$$$$\  $$\$$\$$ | $$$$$$  |
$$ |       \$$\$$  / $$  __|\______|$$  ____/ $$ \$$$$ |  $$ | \_____$$\\______|$$  __$$\ $$ \$$$$ |$$  __$$<
$$ |  $$\   \$$$  /  $$ |           $$ |      $$ |\$$$ |  $$ | $$\   $$ |       $$ /  $$ |$$ |\$$$ |$$ /  $$ |
\$$$$$$  |   \$  /   $$$$$$$$\      $$$$$$$$\ \$$$$$$  /$$$$$$\\$$$$$$  |        $$$$$$  |\$$$$$$  /\$$$$$$  |
 \______/     \_/    \________|     \________| \______/ \______|\______/         \______/  \______/  \______/

版权所有 © 2016 Payatu Technologies Pvt. Ltd.

对换行符和空白字符处理不当,导致 CDOMStringDataList::InitFromString 中发生越界读取。 该缺陷可用于泄漏 MSHTML.DLL 的基址,从而有效绕过**地址空间布局随机化(ASLR)**。

受影响版本

  • Internet Explorer 9
  • Internet Explorer 10
  • Internet Explorer 11

测试环境

  • IE: 10 & 11
  • KB: KB3087038
  • OS: Windows 7 SP1 x86

安全公告

  • http://www.payatu.com/advisory-ie_cdomstringdatalist/
  • https://technet.microsoft.com/library/security/MS15-112
  • http://www.zerodayinitiative.com/advisories/ZDI-15-547/

博客文章

http://www.payatu.com/from-crash-to-exploit/

作者

Ashfaq Ansari

ashfaq[at]payatu[dot]com

@HackSysTeam | 博客 | null

Payatu Technologies

http://www.payatu.com/

已举办的工作坊

  • 从崩溃到利用:CVE-2015-6086

http://hacksys.vfreaks.com

HackSys Team

下载工具