Two security researchers plan to reveal evidence and publish a research paper about a new zero-day exploit in the Microsoft Edge browser. Microsoft has not yet been informed of the details of this vulnerability.
On November 1st, it was announced via tweet that Microsoft Edge had been compromised once again. The proof was an image showing the browser launching the popular Windows Calculator app.
The exploit's creator, Yushi Liang, informed his followers that his goal was to escape the browser sandbox and that he collaborated with Alexander Kochkov to achieve this. The two experts' efforts were hampered by a "crash bug in the text editor" that Liang used to write the exploit code.
Liang said they were focused on developing a stable exploit and achieving complete code escape from the sandbox. The duo were also looking for a method of privilege escalation to SYSTEM, which would amount to full control of the machine.
The expert found the zero-day bug with the help of the Wadi Fuzzer utility from SensePost.
Profit from Edge RCE exploit
The market for Zero-Days is strong and there are several vulnerability brokers ready to offer attractive compensation to developers of new penetration codes targeting browsers.
Zerodium pays $50,000 for a Zero-Day remote code execution (RCE) exploit and doubles the payout when it manages to bypass the sandbox.
Coseinc's Pwnorama program offers up to $30,000 for an RCE exploit in Microsoft's browser and increases the reward to up to $80,000 if accompanied by local privilege escalation.
Vulnerability brokers aren't the only ones offering big payouts for exploits. This year's edition of the Pwn2Own computer hacking competition is offering $60,000 for an exploit that can bypass the Microsoft Edge sandbox.
