Exploitation Summary
EIP tracks 2 public exploits for CVE-2019-0555. PoCs published by Google Security Research, kai6u.
AI-analyzed exploit summary The exploit leverages insecure sharing of the XmlDocument class across process boundaries in Windows Runtime, allowing an AppContainer sandboxed application to escape the Edge Content LPAC sandbox via XSLT script execution in the Runtime Broker. The PoC demonstrates privilege escalation by injecting a DLL into the MicrosoftEdgeCP process.
Description
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Exploits (2)
The exploit leverages insecure sharing of the XmlDocument class across process boundaries in Windows Runtime, allowing an AppContainer sandboxed application to escape the Edge Content LPAC sandbox via XSLT script execution in the Runtime Broker. The PoC demonstrates privilege escalation by injecting a DLL into the MicrosoftEdgeCP process.
This repository contains a proof-of-concept exploit for CVE-2019-0555, demonstrating an Edge sandbox escape via insecure XmlDocument sharing across process boundaries using BadgeUpdateManager, TileFlyoutUpdateManager, and ToastNotificationManager.
References (3)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H