header-logo
Suggest Exploit
vendor:
Xbox-SystemOS
by:
unknownv2 & mon0
8,8
CVSS
HIGH
Privilege Escalation
N/A
CWE
Product Name: Xbox-SystemOS
Affected Version From: 10.0.14393.2152
Affected Version To: 10.0.14393.2152
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Xbox
2016

Xbox-SystemOS Exploit

This exploit is for Xbox-SystemOS version 10.0.14393.2152 (rs1_xbox_rel_1610 161208-1218) fre, 12/14/2016. It is not sufficient to start an .exe via shellcode. Exploiters are encouraged to be creative and find a way to invoke edge engine when console is offline.

Mitigation:

N/A
Source

Exploit-DB raw data:

For Xbox-SystemOS version: 10.0.14393.2152 (rs1_xbox_rel_1610 161208-1218) fre, 12/14/2016

Other versions will most likely need modifications to the script. 

**Credits**:
- https://github.com/theori-io/chakra-2016-11
- https://bugs.chromium.org/p/project-zero/issues/detail?id=952
- https://bugs.chromium.org/p/project-zero/issues/detail?id=945

**Info**:
It is not sufficient to start an .exe via shellcode ;)

Exploiters, be creative!

It is desired to find a way to invoke edge engine when console is offline

Greets from unknownv2 & mon0 _


Download: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44644.zip