Microsoft Internet Explorer XSS Filter CVE-2014-6328 Security Bypass Vulnerability
BID:71460
Info
Microsoft Internet Explorer XSS Filter CVE-2014-6328 Security Bypass Vulnerability
| Bugtraq ID: | 71460 |
| Class: | Design Error |
| CVE: |
CVE-2014-6328 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2014 12:00AM |
| Updated: | Dec 12 2014 12:55AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Internet Explorer 9 Microsoft Internet Explorer 8 Avaya Messaging Application Server 5.2 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer XSS Filter CVE-2014-6328 Security Bypass Vulnerability
Microsoft Internet Explorer is prone to a security-bypass vulnerability that affects the XSS Filter.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content.
An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application. This may allow the attacker to steal cookie-based authentication credentials and other sensitive data that may aid in further attacks. Other attacks are possible.
Internet Explorer 8, 9, 10, and 11 are vulnerable.
Microsoft Internet Explorer is prone to a security-bypass vulnerability that affects the XSS Filter.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content.
An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application. This may allow the attacker to steal cookie-based authentication credentials and other sensitive data that may aid in further attacks. Other attacks are possible.
Internet Explorer 8, 9, 10, and 11 are vulnerable.
Exploit / POC
Microsoft Internet Explorer XSS Filter CVE-2014-6328 Security Bypass Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Microsoft Internet Explorer XSS Filter CVE-2014-6328 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Internet Explorer XSS Filter CVE-2014-6328 Security Bypass Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Internet Explorer HomePage (Microsoft)