|
|||
Rule General Information |
---|
Release Date: | 2017-03-23 | |
Rule Name: | WEB-CLIENT Microsoft Internet Explorer Remote Privilege Escalation Vulnerability (CVE-2017-0154) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application. | |
Impact: | An attacker can abtain more privileges which he is not entitled to by exloiting the vulnerability, such as executing arbitrary code, deleting files, viewing sensitive information, changing configurations. | |
Affected OS: | Windows | |
Reference: | SecurityFocusBID:96766 SecurityTrackerID:1038008 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0154 |
|
Solutions |
---|
The vendor has updated advisory on its official website. Please check it for more information. |