2019年5月8日 星期三

TrendLabs: Zero-day XML External Entity (XXE) Injection Vulnerability in Internet Explorer Can Let Attackers Steal Files, System Info


Figure 1. A malicious XML file that specifies the files to extract from the user’s system
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/zero-day-xml-external-entity-xxe-injection-vulnerability-in-internet-explorer-can-let-attackers-steal-files-system-info/

沒有留言:

張貼留言