PT-2014-1608 · Microsoft · Internet Explorer
James Forshaw
·
Publicado
2014-08-12
·
Atualizado
2025-03-14
·
CVE-2014-2817
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6 through 11
Description
The issue allows an attacker to elevate privileges in Internet Explorer. While these vulnerabilities do not enable the execution of arbitrary code on their own, they can be used in conjunction with other vulnerabilities, such as remote code execution vulnerabilities, to take advantage of elevated privileges and potentially execute arbitrary code. An attacker could exploit these vulnerabilities by using a crafted web site.
Recommendations
For Microsoft Internet Explorer versions 6 through 11, update to a version that includes the fix for this issue to prevent privilege escalation. As a temporary workaround, consider restricting access to potentially vulnerable web sites to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer