vendor:
Internet Explorer
by:
Benjamin Tobias Franz
5.5
CVSS
MEDIUM
Local Resource Enumeration
200
CWE
Product Name: Internet Explorer
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:microsoft:internet_explorer
Platforms Tested: Windows
2004
Local Resource Enumeration Vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer is reported prone to a local resource enumeration vulnerability. It is reported that the vulnerability exists because when handling 'res://' requests for local resources, Internet Explorer behavior may reveal the existence of local files. An attacker may employ information that is harvested in this manner to aid in further attacks that are launched against a target computer.
Mitigation:
It is recommended to update to the latest version of Internet Explorer to mitigate this vulnerability.