Bird_banner_small4
Microsoft Internet Explorer URI Redirection Security Bypass
TSL ID FSC20100203-04
CVE ID(s) CVE-2010-0255
Severity Moderate
Description

An information disclosure vulnerability has been reported in Microsoft Internet Explorer. The vulnerability is due to an error when content is rendered from local files in such a manner that exposes information to malicious websites.

An attacker can exploit this vulnerability by enticing a user to download certain files and subsequently using those files to reveal information from the compromised host.

The vendor, Microsoft, has released information regarding this vulnerability, which is available at:

http://www.microsoft.com/technet/security/advisory/980088.mspx

Affected Products
  • Microsoft Internet Explorer 5.01
  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 7.0
  • Microsoft Internet Explorer 8
CVSS Score Base 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N):
  • Access vector is NETWORK
  • Access complexity is MEDIUM
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is PARTIAL
  • Impact of this vulnerability on data integrity is NONE
  • Impact of this vulnerability on data availability is NONE
Temporal 3.7 (E:U/RL:U/RC:C):
  • The exploitability level of this vulnerability is UNPROVEN
  • The remediation level of this vulnerability is UNAVAILABLE
  • The report confidence level of this vulnerability is CONFIRMED