Microsoft Internet Explorer 9 through 11 mishandles .url files from the Internet zone, which allows remote attackers to bypass intended access restrictions via a crafted file, aka "Internet Explorer Security Feature Bypass."
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92827 | vdb entry |
http://zerodayinitiative.com/advisories/ZDI-16-506/ | vdb entry third party advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-104 | vendor advisory |
http://www.securitytracker.com/id/1036788 | vdb entry |