PT-2007-4447 · Microsoft · Internet Explorer
Published
2007-06-11
·
Updated
2021-07-23
·
CVE-2007-3164
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Internet Explorer version 7
Description:
The issue concerns a potential phishing attack when Microsoft Internet Explorer 7 prompts for HTTP Basic Authentication for an IDN web site. It uses ACE labels for the domain name in the status bar but internationalized labels in the authentication dialog. This discrepancy might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels.
Recommendations:
For Microsoft Internet Explorer version 7, consider avoiding the use of internationalized domain names in authentication dialogs until a fix is available. As a temporary workaround, users should be cautious when interpreting domain names in authentication prompts to minimize the risk of phishing attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer