First published: Wed Feb 12 2014(Updated: )
Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =8 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0268 is classified as a critical vulnerability due to its potential for privilege escalation.
To fix CVE-2014-0268, users should update Microsoft Internet Explorer to the latest version available.
CVE-2014-0268 affects Microsoft Internet Explorer versions 8, 9, 10, and 11.
CVE-2014-0268 enables remote attackers to bypass Mandatory Integrity Control protection mechanisms.
Yes, CVE-2014-0268 can be exploited through crafted websites that target vulnerable versions of Internet Explorer.