Internet Explorer CSS recursive call memory corruption

This is one of the most recent exploits available for the Windows platform running IE browser. This exploit is known to affect Windows 7 and Windows 2008 server with IE 8 as the default browser. The working process of this exploit is similar to the one we just discussed in the previous recipe. So let us quickly test it. Our target machine is a Windows 7 ultimate edition with IE 8 (unpatched) running as the default browser.

Getting ready

We will start with launching the msfconsole. Our exploit in this recipe is exploit/windows/browser/ms11_003_ie_css_import and our payload will be windows/meterpreter/bind_tcp which will help in gaining shell connectivity with the target machine.

How to do it... ...

Get Metasploit Penetration Testing Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.