PT-2015-3016 · Microsoft · Internet Explorer

Published

2015-12-08

·

Updated

2018-10-12

·

CVE-2015-6164

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 9 through 11
Description The issue arises from improper implementation of a cross-site scripting (XSS) protection mechanism in Microsoft Internet Explorer, allowing remote attackers to bypass the Same Origin Policy via a crafted web site. This could enable an attacker to access information from one domain and inject it into another domain. The vulnerability itself does not allow arbitrary code execution but could be exploited in conjunction with another vulnerability to take advantage of elevated privileges.
Recommendations For Microsoft Internet Explorer versions 9 through 11, as a temporary workaround, consider disabling the XSS filter until a patch is available. Restrict access to potentially vulnerable web sites to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00220
CVE-2015-6164

Affected Products

Internet Explorer