Proof-of-Concept exploit for jscript9 bug (MS16-063) w/ CFG bypass
Tested on Windows 10 IE11 (modern.ie).
http://theori.io/research/chakra-jit-cfg-bypass
- Download exploit/jscript_win10_jit.html to a directory.
- Serve the directory using a webserver (or python's simple HTTP server).
- Browse with a victim IE to
jscript_win10_jit.html
. - (Re-fresh or re-open in case it doesn't work; It's not 100% reliable.)