MS.IE.File.Download.Security.Warning.Bypass

description-logoDescription

The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.

affected-products-logoAffected Products

Microsoft Internet Explorer 6.x

Impact logoImpact

Successful exploit allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.

recomended-action-logoRecommended Actions

Disable Active Scripting support and the "Hide extension for known file types" option.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-03-28 14.582 Sig Added