PT-2014-2626 · Microsoft+1 · Internet Explorer+1

Published

2014-01-29

·

Updated

2014-02-21

·

CVE-2013-2747

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Courion Access Risk Management Suite version 8 Update 9
Description The issue concerns the password reset feature, which allows remote authenticated users to bypass intended Internet Explorer usage restrictions. This can be achieved by utilizing keyboard shortcuts to navigate the file system and open a command prompt, ultimately enabling the execution of arbitrary commands.
Recommendations For Courion Access Risk Management Suite version 8 Update 9, consider restricting access to the password reset feature until a fix is available, and limit the use of keyboard shortcuts within the application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2747

Affected Products

Courion Access Risk Management Suite
Internet Explorer