Skip to content

Commit

Permalink
update themebleed repo link
Browse files Browse the repository at this point in the history
  • Loading branch information
carrot-c4k3 committed May 19, 2024
1 parent ae52c78 commit 4f38ab0
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion content/themebleed/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,7 @@ I developed a PoC for this issue. The PoC consists of two components, an SMB ser
I chose to use an attacker controlled SMB server for this because a `.theme` file may point to a `.msstyle` path on a remote SMB share. Since the SMB share is attacker controlled, it can easily exploit the TOCTOU bug in `ReviseVersionIfNecessary` by returning a validly signed file when the client first requests it to check the signature, and then a malicious one when the client loads the DLL.
The PoC can be found here: [https://github.com/gabe-k/themebleed](https://github.com/gabe-k/themebleed)
The PoC can be found here: [https://github.com/exploits-forsale/themebleed](https://github.com/exploits-forsale/themebleed)
## Environment Prep
Expand Down

0 comments on commit 4f38ab0

Please sign in to comment.