PT-2014-2626 · Microsoft+1 · Internet Explorer+1
Published
2014-01-29
·
Updated
2014-02-21
·
CVE-2013-2747
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Courion Access Risk Management Suite version 8 Update 9
Description
The issue concerns the password reset feature, which allows remote authenticated users to bypass intended Internet Explorer usage restrictions. This can be achieved by utilizing keyboard shortcuts to navigate the file system and open a command prompt, ultimately enabling the execution of arbitrary commands.
Recommendations
For Courion Access Risk Management Suite version 8 Update 9, consider restricting access to the password reset feature until a fix is available, and limit the use of keyboard shortcuts within the application to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Courion Access Risk Management Suite
Internet Explorer