CVE-2011-1347

Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:26

Type Values Removed Values Added
References () http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011 - () http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011 -
References () http://twitter.com/aaronportnoy/statuses/45642180118855680 - () http://twitter.com/aaronportnoy/statuses/45642180118855680 -
References () http://twitter.com/msftsecresponse/statuses/45646985998516224 - () http://twitter.com/msftsecresponse/statuses/45646985998516224 -
References () http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own - () http://www.computerworld.com/s/article/9214002/Safari_IE_hacked_first_at_Pwn2Own -
References () http://www.securityfocus.com/bid/46821 - () http://www.securityfocus.com/bid/46821 -
References () http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367 - () http://www.zdnet.com/blog/security/pwn2own-2011-ie8-on-windows-7-hijacked-with-3-vulnerabilities/8367 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-057 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-057 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/66064 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/66064 -
References () https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011 - () https://threatpost.com/en_us/blogs/pwn2own-winner-stephen-fewer-031011 -

Information

Published : 2011-03-10 20:55

Updated : 2024-11-21 01:26


NVD link : CVE-2011-1347

Mitre link : CVE-2011-1347

CVE.ORG link : CVE-2011-1347


JSON object : View

Products Affected

microsoft

  • internet_explorer
  • windows_7