PT-2007-4447 · Microsoft · Internet Explorer

Published

2007-06-11

·

Updated

2021-07-23

·

CVE-2007-3164

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer version 7
Description: The issue concerns a potential phishing attack when Microsoft Internet Explorer 7 prompts for HTTP Basic Authentication for an IDN web site. It uses ACE labels for the domain name in the status bar but internationalized labels in the authentication dialog. This discrepancy might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels.
Recommendations: For Microsoft Internet Explorer version 7, consider avoiding the use of internationalized domain names in authentication dialogs until a fix is available. As a temporary workaround, users should be cautious when interpreting domain names in authentication prompts to minimize the risk of phishing attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3164

Affected Products

Internet Explorer