First published: Thu Jun 16 2011(Updated: )
Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =7 | |
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =8 | |
Microsoft Windows 7 | ||
Microsoft Windows Server 2008 Itanium | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1258 has a severity rating of important, indicating a potential for significant impact on information disclosure.
To fix CVE-2011-1258, it is essential to apply the security updates provided by Microsoft for the affected versions of Internet Explorer.
CVE-2011-1258 affects Internet Explorer versions 6, 7, and 8.
Yes, CVE-2011-1258 allows user-assisted remote attackers to obtain sensitive information from different domains or zones.
No, CVE-2011-1258 does not affect newer versions of Windows or Internet Explorer beyond version 8.