Security restrictions bypass in Microsoft Internet Explorer - CVE-2019-0995
Published: May 15, 2019
Microsoft Internet Explorer
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an error within urlmon.dll when handling certain Mark of the Web queries. A remote attacker can create a specially crafted file, trick the victim to download and open it with Internet Explorer and bypass Mark of the Web warnings or restrictions for files downloaded or created in a specific way.