This video shows how we patched a Windows 0-day vulnerability CVE-2017-0038, published by Google Project Zero before Microsoft provided an official fix. The video shows how Project Zero's poc.emf actually causes out-of-bounds memory to be read and displayed as pixels in a browser (where JavaScript could read each pixel and extract bytes). You can see how tabs running in different IE processes show a different image. Then we take our .0pp patch file, build it and deploy it to our local 0patch Agent. When IE is launched again, the patch gets applied, effectively adding the missing validation to the processing of an EMF file: if width and height of the image are such that the amount of pixel data is insufficient, processing of the image is cancelled. (For a good measure we also added an "Exploit Attempt Blocked" popup.) Finally you can see that disabling the patch instantly resurrects the vulnerability.
Find more details in our blog post at https://0patch.blogspot.com/2017/02/0....
https://0patch.com
/ 0patch
https://0patch.blogspot.com