/Edge0day.exe

CVE-2020-????

Primary LanguageHTMLGNU General Public License v3.0GPL-3.0

Edge0day [CVE-2020-????]

CVSSv2: 11/10

Root cause

The URI handler calculator: launches calc.exe via ShellExecute and Windows does not warn you with an alert box either! :O!!

PoC

Open up ./poc/poc.html with Microsoft Edge, click the link, and oh noes calculator opens!1!1 :OOOOOOOOOOOOOOOOOOO

[b1ack0wl]