CVE-2017-17692
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 79%
from disclosure to weapon0 days
Published on NVDDec 21
1st PoCDec 20
metasploitNov 8
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/43376unverifiedgithubgithub.com/specloli/CVE-2017-17692★ 0cve_referencepacketstormsecurity.com/files/145510/Samsung-Internet-Browser-SOP-Bypass.htmlunverifiedcve_referencewww.exploit-db.com/exploits/43376/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/145510/Samsung-Internet-Browser-SOP-Bypass.htmlhttps://datarift.blogspot.in/p/samsung-interent-browser-sop-bypass-cve.htmlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/samsung_browser_sop_bypass.rbhttps://www.exploit-db.com/exploits/43376/