Outlook Home Page – Another Ruler Vector

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

[Ruler](https://github.com/sensepost/ruler) has become a go to tool for us on external engagements, easily turning compromised mailbox credentials into shells. This has resulted in security being pushed forward and Microsoft responding with patches for the two vectors used in Ruler, namely rules and forms. These were patched with [KB3191938](https://support.microsoft.com/en-us/help/3191938/descriptionofthesecurityupdateforoutlook2013june13-2017) and [KB4011091](https://support.office.com/en-us/article/Custom-form-script-is-now-disabled-by-default-bd8ea308-733f-4728-bfcc-d7cce0120e94) respectively. This puts us back into the cat and mouse game of attack versus defence, with attack needing to find a new vector. Turns out the rules of three holds true, and where two vulnerabilities lurk, a third surely exists. tl;dr There is a new attack built into Ruler. New version of Ruler: https://github.com/sensepost/ruler But you need to read this post to get the exploit ;) ### The Home Page...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息