The broker EditWith feature in Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the AppContainer protection mechanism and gain privileges via a DelegateExecute launch of an arbitrary application, as demonstrated by a transition from Low Integrity to Medium Integrity, aka Internet Explorer Elevation of Privilege Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Internet_explorer | Microsoft | 8 (including) | 8 (including) |
Internet_explorer | Microsoft | 9 (including) | 9 (including) |
Internet_explorer | Microsoft | 10 (including) | 10 (including) |
Internet_explorer | Microsoft | 11 (including) | 11 (including) |