First published: Wed Dec 09 2015(Updated: )
Microsoft Internet Explorer 8 through 11 and Microsoft Edge mishandle HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Browser XSS Filter Bypass Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =8 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6144 has a high severity rating due to its ability to bypass the cross-site scripting protection in affected browsers.
CVE-2015-6144 affects Internet Explorer versions 8, 9, 10, and 11.
To mitigate CVE-2015-6144, users should apply the latest security updates and patches from Microsoft.
CVE-2015-6144 can be exploited to facilitate cross-site scripting (XSS) attacks, compromising the security of web applications.
Yes, Microsoft Edge is also affected by CVE-2015-6144 as it mishandles HTML attributes in HTTP responses.