vendor:
Internet Explorer
by:
Liu Die Yu
7.5
CVSS
HIGH
Unauthorized Access
264
CWE
Product Name: Internet Explorer
Affected Version From: Internet Explorer 6
Affected Version To: Internet Explorer 6 SP1
Patch Exists: YES
Related CWE:
CPE: a:microsoft:internet_explorer:6
Platforms Tested: Windows
2003
Unauthorized Access to Local Resources in Microsoft Internet Explorer
The issue allows unauthorized access to local resources in Microsoft Internet Explorer. By adding an additional slash when specifying a resource via the file:// or res:// protocols, the restrictions imposed by Internet Explorer version 6 SP1 can be bypassed. This can potentially aid in the exploitation of other vulnerabilities, allowing an attacker to create files on a client system and reference them using these protocols. The exact cause of the issue is currently under investigation.
Mitigation:
Apply the latest security patches and updates provided by Microsoft. Avoid visiting untrusted websites and exercise caution when clicking on links or downloading files.