PT-2011-3078 · Microsoft · Windows 7+1

Published

2011-03-10

·

Updated

2021-07-23

·

CVE-2011-1347

CVSS v2.0

8.8

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer 8 on Windows 7
Description The issue allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process. This was demonstrated by Stephen Fewer during a Pwn2Own competition at CanSecWest 2011.
Recommendations For Microsoft Internet Explorer 8 on Windows 7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-1347
ZDI-11-249

Affected Products

Internet Explorer 8
Windows 7