Microsoft Internet Explorer Cumulative Security Update
Last Update Date:
15 Jan 2016
Release Date:
13 Jan 2016
3768
Views
RISK: High Risk
TYPE: Clients - Browsers
- Scripting Engine Memory Corruption Vulnerability
A remote code execution vulnerability exists in the way that the VBScript engine renders when handling objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. - Internet Explorer Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. The update addresses the vulnerability by helping to ensure that cross-domain policies are properly enforced in Internet Explorer.
Impact
- Elevation of Privilege
- Remote Code Execution
System / Technologies affected
- Internet Explorer 7
- Internet Explorer 8
- Internet Explorer 9
- Internet Explorer 10
- Internet Explorer 11
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS16-001
Vulnerability Identifier
Source
Related Link
Share with