CVE-2018-0949

MEDIUM

Microsoft Internet Explorer - Auth Bypass

Title source: llm
STIX 2.1

Description

A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104622
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041258

Scores

CVSS v3 6.5
EPSS 0.1098
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

Status published
Products (3)
microsoft/internet_explorer 10
microsoft/internet_explorer 11
microsoft/internet_explorer 9
Published Jul 11, 2018
Tracked Since Feb 18, 2026