sandbox/win/sandbox_poc/pocdll/spyware.cc uses ::GetAsyncKeyState() incorrectly |
|
Issue descriptionThe documentation states that only the hi-order bit is reliable : https://docs.microsoft.com/en-us/windows/desktop/api/winuser/nf-winuser-getasynckeystate but https://cs.chromium.org/chromium/src/sandbox/win/sandbox_poc/pocdll/spyware.cc?q=GetAsyncKeyState&sq=package:chromium&dr=C uses 0x1 as a mask (extracting the lo-order bit). |
|
►
Sign in to add a comment |
|