PT-2015-3016 · Microsoft · Internet Explorer
Published
2015-12-08
·
Updated
2018-10-12
·
CVE-2015-6164
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 9 through 11
Description
The issue arises from improper implementation of a cross-site scripting (XSS) protection mechanism in Microsoft Internet Explorer, allowing remote attackers to bypass the Same Origin Policy via a crafted web site. This could enable an attacker to access information from one domain and inject it into another domain. The vulnerability itself does not allow arbitrary code execution but could be exploited in conjunction with another vulnerability to take advantage of elevated privileges.
Recommendations
For Microsoft Internet Explorer versions 9 through 11, as a temporary workaround, consider disabling the XSS filter until a patch is available. Restrict access to potentially vulnerable web sites to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer