CVE-2011-0038 describes an untrusted search path vulnerability in Microsoft Internet Explorer 8, impacting various Windows operating systems including Windows XP, Vista, 7, and Server versions. This flaw allows local users to potentially gain elevated privileges by tricking IE8 into loading a malicious IEShims.dll from the current working directory. With a CVSS score of 9.3, this vulnerability is critical, indicating a network-based attack with medium complexity that could lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, its high FAUCET Risk Score of 96/100 suggests a severe potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.