PT-2015-1660 · Microsoft · Internet Explorer
Publicado
2015-07-14
·
Atualizado
2018-10-12
·
CVE-2015-2413
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 6 through 11
Description
The issue is related to the improper handling of requests for module resources, which could allow a remote attacker to determine the existence of specific local files using a specially crafted request. This could potentially be used to obtain information that could aid in further compromising the affected system. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For Internet Explorer versions 6 through 11, update to a version that properly handles requests for module resources to prevent information disclosure.
As a temporary workaround, consider restricting access to module resources to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer