PT-2014-1120 · Microsoft · Internet Explorer
James Forshaw
·
Publicado
2014-06-10
·
Atualizado
2018-10-12
·
CVE-2014-1777
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 10 through 11
Description
The issue is caused by the program's inability to properly check permissions when installing local files. This allows an attacker to gain unauthorized access to confidential information in local files. An information disclosure vulnerability exists within Internet Explorer during validation of local file installation, enabling remote attackers to read local files on the client via a crafted web site.
Recommendations
For Internet Explorer versions 10 and 11, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to sensitive local files until a patch is available.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer