PT-2015-1660 · Microsoft · Internet Explorer
Published
2015-07-14
·
Updated
2018-10-12
·
CVE-2015-2413
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 6 through 11
Description
The issue is related to the improper handling of requests for module resources, which could allow a remote attacker to determine the existence of specific local files using a specially crafted request. This could potentially be used to obtain information that could aid in further compromising the affected system. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For Internet Explorer versions 6 through 11, update to a version that properly handles requests for module resources to prevent information disclosure.
As a temporary workaround, consider restricting access to module resources to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer