Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4695

Overview

Vulnerability Score 6.9 6.9
CVE Id CVE-2011-4695
Last Modified 05 Mar 2012 12:00:00
Published 07 Dec 2011 03:55:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4695

Summary

Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Vulnerable Systems

Operating System

  • Microsoft Windows 7 -


References

MLIST - [dailydave] 20111206 Flash 0day

MISC - http://partners.immunityinc.com/movies/VulnDisco-Flash0day-v2.mov


Last Updated: 27 May 2016 10:57:50