MS.IE.XSS.Filter.Information.Disclosure

description-logoDescription

This indicates an attack attempt against an Information Disclosure vulnerability in Microsoft Internet Explorer.
This issue is caused by an error when the XSS filter handles malicious Javascript codes. It may allow remote attackers to gain sensitive information from vulnerable systems by sending a crafted web page.

affected-products-logoAffected Products

Internet Explorer 8 for Windows XP Service Pack 3
Internet Explorer 8 for Windows XP Professional x64 Edition Service Pack 2
Internet Explorer 8 for Windows Server 2003 Service Pack 2
Internet Explorer 8 for Windows Server 2003 x64 Edition Service Pack 2
Internet Explorer 8 in Windows Vista Service Pack 2
Internet Explorer 8 in Windows Vista x64 Edition Service Pack 2
Internet Explorer 8 in Windows Server 2008 for 32-bit Systems Service Pack 2
Internet Explorer 8 in Windows Server 2008 for x64-based Systems Service Pack 2
Internet Explorer 8 in Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1
Internet Explorer 8 in Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1
Internet Explorer 8 in Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1
Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for suggested workaround.
http://www.microsoft.com/technet/security/Bulletin/MS11-099.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)