Cross-Zone Drag-and-Drop Vulnerability in Microsoft Internet Explorer
CVE-2011-2382
Currently unrated
What is CVE-2011-2382?
This vulnerability in Microsoft Internet Explorer versions 8 and earlier, as well as the Internet Explorer 9 beta, fails to properly restrict drag-and-drop actions across different security zones. This flaw can be exploited by user-assisted remote attackers, allowing them to read sensitive cookie files through carefully crafted IFRAME elements containing file: URLs. This issue has potential implications for user privacy and security, particularly in relation to cookiejacking attacks.