Lucene search

K
zdiThomas VanhoutteZDI-16-275
HistoryMay 10, 2016 - 12:00 a.m.

Microsoft Internet Explorer Add-on Installer Enhanced Protected Mode Information Disclosure Vulnerability

2016-05-1000:00:00
Thomas Vanhoutte
www.zerodayinitiative.com
20

0.534 Medium

EPSS

Percentile

97.6%

This vulnerability allows remote attackers to bypass the Enhanced Protected Mode sandbox of vulnerable installations of Microsoft Internet Explorer and disclose file contents. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Internet Explorer Add-on Installer component. An attacker can use this component to read the contents of any file that the current user has access to.