Information disclosure in Microsoft Internet Explorer - CVE-2011-1252
Published: March 20, 2017 / Updated: November 20, 2020
Microsoft Internet Explorer
Detailed vulnerability description
The vulnerability exists due to improper handling of content using specific strings when sanitizing HTML by Internet Explorer. A remote unauthenticated attacker can trick the victim into opening a specially crafted Web site thet uses toStaticHTML API and gain access to potentially sensitive information on the system.
Successful exploitation of this vulnerability results in information disclosure.