PT-2014-1123 · Microsoft · Internet Explorer
James Forshaw
·
Published
2014-02-11
·
Updated
2018-10-12
·
CVE-2014-0268
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 8 through 11
Description
The issue is related to the improper restriction of file installation and registry-key creation, allowing remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site. This is an elevation of privilege issue that exists during validation of local file installation and during secure creation of registry keys.
Recommendations
For Microsoft Internet Explorer versions 8 through 11, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer