Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging object confusion in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_explorer | Microsoft | 7 (including) | 7 (including) |
Internet_explorer | Microsoft | 8 (including) | 8 (including) |
Internet_explorer | Microsoft | 9 (including) | 9 (including) |
Internet_explorer | Microsoft | 10 (including) | 10 (including) |
Internet_explorer | Microsoft | 11 (including) | 11 (including) |