Security issue in Windows 10 Edge Browser

WinRT PDF, is the default Windows 10 PDF Reader application. However, this app is endangering Edge in a way similar to how Flash, Java, and Acrobat applications have exposed Internet users in recent years.Edge hacker

The Windows Runtime (WinRT) PDF Renderer library, or simply WinRT PDF, is a powerful component built into recent versions of the Windows operating system that allows developers to easily integrate a s PDF within their applications.

Η βιβλιοθήκη χρησιμοποιείται από πολλές εφαρμογές που διανέμονται μέσω του Windows Store. Συμπεριλαμβάνεται σαν προεπιλεγμένη εφαρμογή Reader για PDF στα Windows 8 και 8.1, αλλά και στον of Windows 10.

Mark Vincent Yason, a security researcher on the X-Force team IBM Research found that WinRT PDF can be exploited in drive-by attacks in the same way that attackers used Flash or Java.

WinRT PDF as mentioned above is a PDF reader that Edge uses by default.

So any PDF file that is embedded inside a web page will open in the library. A smart intruder can exploit WinRT PDF with a PDF file that could be hidden by using an iframe outside the CSS screen.

Ο This code will exploit the WinRT PDF vulnerability in the same way exploit kits like Angler or Neutrino use to deliver malicious Flash, Java, or Silverlight payloads.

Mr. Yason will present a more in-depth presentation of this attack scenario at of RSA Security in San Francisco.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).