Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-119 | vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-118 | vendor advisory |
http://www.securitytracker.com/id/1036993 | vdb entry |
http://www.securityfocus.com/bid/93382 | vdb entry |
https://www.exploit-db.com/exploits/40606/ | exploit |
http://www.securitytracker.com/id/1036992 | vdb entry |