HomeinetSecurity issue in Windows 10's Edge Browser

Security issue in Windows 10's Edge Browser

WinRT PDF is the default PDF reader for Windows 10. However, this particular app puts Edge at risk in a similar way that Flash, Java, and Acrobat apps have exposed internet users in recent years.Edge hacker

The Windows Runtime (WinRT) PDF Renderer library, or simply WinRT PDF, is a powerful component built into recent versions of the Windows operating system that allows developers to easily integrate a PDF viewing feature into their applications.

The library is used by many applications distributed through the Windows Store. It is included as the default PDF Reader application in Windows 8 and 8.1, as well as in the Edge browser in Windows 10.

Mark Vincent Yason, a security researcher at IBM's X-Force Advanced Research team, discovered that WinRT PDF can be exploited in drive-by attacks in the same way that attackers used Flash or Java.

WinRT PDF, as mentioned above, is the PDF reader that Edge uses by default.

So any PDF file embedded within a web page will open within the library. A clever attacker could exploit WinRT PDF with a PDF file that could be opened secretly, using an iframe off-screen with CSS.

The malicious code will exploit the WinRT PDF vulnerability in the same way that exploit kits like Angler or Neutrino use to deliver malicious Flash, Java, or Silverlight payloads.

Mr. Yason will present a more in-depth presentation of this attack scenario at the RSA Security conference in San Francisco.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS