Blog | G5 Cyber Security

Anatomy of an exploit inside the CVE-2013-3893 Internet Explorer zero-day Part 2

In Part One, we looked at how the Internet Explorer (IE) exploit got its foot in the door of Windows. In Part Two, we will follow the exploit as it takes over IE, suppresses Data Execution Prevention (DEP) and reaches a point where it can run pretty much any program code it likes just as if you had downloaded it yourself. The exploit makes a good example for study, because it can theoretically be used against IE from version 6 to 11. It works despite DEP and ASLR, so we arent giving away secrets.”]

Source: https://nakedsecurity.sophos.com/2013/10/25/anatomy-of-an-exploit-inside-the-cve-2013-3893-internet-explorer-zero-day-part-2/

Exit mobile version