Flash Broker-Based Sandbox Escape Via Forward Slash

FlashBroker is vulnerable to an NTFS junction attack to write an arbitrary file to the filesystem under user permissions. There is a bad check in FlashBroker BrokerCreateFile method and BrokerMoveFileEx method. FlashBroker only considers “” as delimiter. If the destination includes “/”, FlashBroker will use a wrong destination folder for check.

Leave a Reply