Sendbox bypass in Microsoft Internet Explorer - #VU18581

 

Sendbox bypass in Microsoft Internet Explorer - #VU18581

Published: May 23, 2019


Vulnerability identifier: #VU18581
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the way Internet Explorer handles loaded .DLL libraries. An attacker who can attack a malicious .dll file to the Internet Explorer process can bypass IE Protected Mode and execute arbitrary JS code with medium integrity permissions.


Affected software

Microsoft Internet Explorer

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins