PT-2013-4210 · Microsoft · Internet Explorer
Fermin J. Serna
·
Publicado
2013-08-14
·
Atualizado
2023-12-07
·
CVE-2013-3186
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 7 through 10
Description
The Protected Mode feature in Microsoft Internet Explorer does not properly implement the Integrity Access Level protection mechanism. This allows remote attackers to obtain medium-integrity privileges by leveraging access to a low-integrity process. An elevation of privilege issue exists in the way Internet Explorer handles process integrity level assignment in specific cases, which could allow arbitrary code to execute with elevated privileges.
Recommendations
For Microsoft Internet Explorer versions 7 through 10, update to a version that properly implements the Integrity Access Level protection mechanism to prevent elevation of privilege attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer