Описание
Microsoft Browser Information Disclosure Vulnerability
An information disclosure vulnerability exists when the Microsoft browser XSS filter is abused to leak sensitive page information. An attacker who successfully exploited the vulnerability could obtain sensitive information from certain web pages.
To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
The update addresses the vulnerability by changing how the XSS filter handles RegEx.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Internet Explorer 10 on Windows Server 2012 | ||
| Internet Explorer 11 on Windows 8.1 for 32-bit systems | ||
| Internet Explorer 11 on Windows 8.1 for x64-based systems | ||
| Internet Explorer 11 on Windows Server 2012 R2 | ||
| Internet Explorer 11 on Windows RT 8.1 | - | |
| Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 | ||
| Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1 | ||
| Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 | ||
| Internet Explorer 11 on Windows 10 for 32-bit Systems | ||
| Internet Explorer 11 on Windows 10 for x64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
EPSS
Связанные уязвимости
The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
Уязвимость браузеров Microsoft Edge и Internet Explorer, позволяющая нарушителю получить конфиденциальную информацию или провести XSS-атаки
EPSS