The broker EditWith feature in Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the AppContainer protection mechanism and gain privileges via a DelegateExecute launch of an arbitrary application, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Internet Explorer Elevation of Privilege Vulnerability."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.zerodayinitiative.com/advisories/ZDI-15-522 | |
http://www.securitytracker.com/id/1033800 | vdb entry third party advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-106 | vendor advisory |