PT-2014-1608 · Microsoft · Internet Explorer
James Forshaw
·
Published
2014-08-12
·
Updated
2025-03-14
·
CVE-2014-2817
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6 through 11
Description
The issue allows an attacker to elevate privileges in Internet Explorer. While these vulnerabilities do not enable the execution of arbitrary code on their own, they can be used in conjunction with other vulnerabilities, such as remote code execution vulnerabilities, to take advantage of elevated privileges and potentially execute arbitrary code. An attacker could exploit these vulnerabilities by using a crafted web site.
Recommendations
For Microsoft Internet Explorer versions 6 through 11, update to a version that includes the fix for this issue to prevent privilege escalation. As a temporary workaround, consider restricting access to potentially vulnerable web sites to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer