Описание
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
Ссылки
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
4.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
Уязвимость браузера Internet Explorer, позволяющая нарушителю получить доступ к информации для перевода её из одного домена в другой
EPSS
4.4 Medium
CVSS3
5.8 Medium
CVSS2