Information disclosure in Microsoft Internet Explorer - CVE-2011-1245

 

Information disclosure in Microsoft Internet Explorer - CVE-2011-1245

Published: December 27, 2016 / Updated: January 9, 2017


Vulnerability identifier: #VU2845
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:A/U:Green
CVE-ID: CVE-2011-1245
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Microsoft Internet Explorer

Detailed vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to improper handling of Javascript during certain processes. A remote attacker can create a specially crafted Web page, trick the victim into visiting it and bypass cross-domain security restrictions and obtain sensitive information from another security zone or domain.

Successful exploitation of the vulnerability results in information disclosure on the vulnerable system.

How to mitigate CVE-2011-1245

Install update from vendor's website:

Internet Explorer 6:
Windows XP Service Pack 3:
https://www.microsoft.com/downloads/details.aspx?FamilyID=c3a8cec0-f947-4d4e-a6ae-c7f4f1f311b0
http://go.microsoft.com/fwlink/?LinkId=208304
Windows XP Professional x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=986f07ae-0fdc-4be2-8a74-5eb56d4300ef
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=b902c58a-9e2f-4352-8d2f-fffda5344598
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=5d8f14d1-85cc-478f-8b50-5c355a331f59
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 with SP2 for Itanium-based Systems:
https://www.microsoft.com/downloads/details.aspx?FamilyID=8afe86fc-58b4-4a95-b047-c09138fa4f5e
http://go.microsoft.com/fwlink/?LinkId=208304

Internet Explorer 7:
Windows XP Service Pack 3:
https://www.microsoft.com/downloads/details.aspx?FamilyID=0b7d0403-8965-4c62-970c-20b561f66713
http://go.microsoft.com/fwlink/?LinkId=208304
Windows XP Professional x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=ed88f183-dd06-46f6-ae8a-a594a752f248
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=5c464287-3dab-4342-a38d-a12719d3b158
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=9d8bbea9-c456-4569-ad96-c2cd0f5fae7e
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 with SP2 for Itanium-based Systems:
https://www.microsoft.com/downloads/details.aspx?FamilyID=f1abfb48-3c8a-4b2d-b739-cc61628b387d
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Vista Service Pack 1 and Windows Vista Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=00c3c176-feff-4022-ac4c-2d4732ca3d78
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=79f52733-44e4-47b6-86ca-1395a095b4e7
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=7d8603b8-bb52-4cf6-be8b-bb3475d30fc5
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=c6d58f64-bdd5-4fe6-96f4-9641b8e7b570
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?FamilyID=f6f6f22c-fc7f-4e96-b6b5-be3c1acecf6e
http://go.microsoft.com/fwlink/?LinkId=208304

Internet Explorer 8:
Windows XP Service Pack 3:
https://www.microsoft.com/downloads/details.aspx?familyid=689c5496-56c4-48a6-9f3d-b5f5aaf3e566
http://go.microsoft.com/fwlink/?LinkId=208304
Windows XP Professional x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=6d3433ee-c2e1-433f-a3d9-c049d66e2190
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=45feb35b-b24e-4160-adb0-d0b7ae530e90
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2003 x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=979d2ec5-5114-4ec7-aa97-e9289c590cbb
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Vista Service Pack 1 and Windows Vista Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=5ea94705-4f76-4b0d-bbbc-afb5e75204bf
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=bc63b233-9db0-4fb1-a61c-fa7e9e44ba10
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=d5d76e90-1cef-47e8-9d8d-2c5a43f42ba3
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2:
https://www.microsoft.com/downloads/details.aspx?familyid=51203a31-368b-4b47-96a5-9e9e5a55cd76
http://go.microsoft.com/fwlink/?LinkId=208304
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1
https://www.microsoft.com/downloads/details.aspx?familyid=59676b71-8b9d-4230-a9e0-b20db3e3ec7e
http://go.microsoft.com/fwlink/?LinkId=208304
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1:
https://www.microsoft.com/downloads/details.aspx?familyid=3a998678-2678-489e-8711-39322663147d
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1:
https://www.microsoft.com/downloads/details.aspx?familyid=c7b2482b-44bf-4c01-99d8-f93868659a24
http://go.microsoft.com/fwlink/?LinkId=208304
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1:
https://www.microsoft.com/downloads/details.aspx?familyid=af6db318-fbec-4286-a3a7-4081620146e5
http://go.microsoft.com/fwlink/?LinkId=208304

Sources