PT-2014-2626 · Microsoft+1 · Internet Explorer+1

Publicado

2014-01-29

·

Atualizado

2014-02-21

·

CVE-2013-2747

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Courion Access Risk Management Suite version 8 Update 9
Description The issue concerns the password reset feature, which allows remote authenticated users to bypass intended Internet Explorer usage restrictions. This can be achieved by utilizing keyboard shortcuts to navigate the file system and open a command prompt, ultimately enabling the execution of arbitrary commands.
Recommendations For Courion Access Risk Management Suite version 8 Update 9, consider restricting access to the password reset feature until a fix is available, and limit the use of keyboard shortcuts within the application to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2747

Produtos afetados

Courion Access Risk Management Suite
Internet Explorer