Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
2017-03-17T00:59:04.307
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.4 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | internet_explorer | 11 | Yes |
Operating System | microsoft | windows_10 | - | No |
Operating System | microsoft | windows_10 | 1511 | No |
Operating System | microsoft | windows_10 | 1607 | No |
Operating System | microsoft | windows_server_2016 | - | No |