CVE-2011-2382

medium
Published 2011-06-03 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
windows microsoftie9
windows microsoftinternet_explorer{"endIncluding":"8"}
windows microsoftinternet_explorer3.0
windows microsoftinternet_explorer3.0.1
windows microsoftinternet_explorer3.0.2
windows microsoftinternet_explorer3.1
windows microsoftinternet_explorer3.2
windows microsoftinternet_explorer4.0
windows microsoftinternet_explorer4.0.1
windows microsoftinternet_explorer4.01
windows microsoftinternet_explorer4.1
windows microsoftinternet_explorer4.5
windows microsoftinternet_explorer4.40.308
windows microsoftinternet_explorer4.40.520
windows microsoftinternet_explorer4.70.1155
windows microsoftinternet_explorer4.70.1158
windows microsoftinternet_explorer4.70.1215
windows microsoftinternet_explorer4.70.1300
windows microsoftinternet_explorer4.71.544
windows microsoftinternet_explorer4.71.1008.3
windows microsoftinternet_explorer4.71.1712.6
windows microsoftinternet_explorer4.72.2106.8
windows microsoftinternet_explorer4.72.3110.8
windows microsoftinternet_explorer4.72.3612.1713
windows microsoftinternet_explorer5
windows microsoftinternet_explorer5.0
windows microsoftinternet_explorer5.0.1
windows microsoftinternet_explorer5.00.0518.10
windows microsoftinternet_explorer5.00.0910.1309
windows microsoftinternet_explorer5.00.2014.0216
windows microsoftinternet_explorer5.00.2314.1003
windows microsoftinternet_explorer5.00.2516.1900
windows microsoftinternet_explorer5.00.2614.3500
windows microsoftinternet_explorer5.00.2919.800
windows microsoftinternet_explorer5.00.2919.3800
windows microsoftinternet_explorer5.00.2919.6307
windows microsoftinternet_explorer5.00.2920.0000
windows microsoftinternet_explorer5.00.3103.1000
windows microsoftinternet_explorer5.00.3105.0106
windows microsoftinternet_explorer5.00.3314.2101
windows microsoftinternet_explorer5.00.3315.1000
windows microsoftinternet_explorer5.00.3502.1000
windows microsoftinternet_explorer5.00.3700.1000
windows microsoftinternet_explorer5.01
windows microsoftinternet_explorer5.1
windows microsoftinternet_explorer5.2.3
windows microsoftinternet_explorer5.5
windows microsoftinternet_explorer5.50.3825.1300
windows microsoftinternet_explorer5.50.4030.2400
windows microsoftinternet_explorer5.50.4134.0100
windows microsoftinternet_explorer5.50.4134.0600
windows microsoftinternet_explorer5.50.4308.2900
windows microsoftinternet_explorer5.50.4522.1800
windows microsoftinternet_explorer5.50.4807.2300
windows microsoftinternet_explorer6
windows microsoftinternet_explorer6.0
windows microsoftinternet_explorer6.00.2462.0000
windows microsoftinternet_explorer6.00.2479.0006
windows microsoftinternet_explorer6.0.2600
windows microsoftinternet_explorer6.00.2600.0000
windows microsoftinternet_explorer6.0.2800
windows microsoftinternet_explorer6.0.2800.1106
windows microsoftinternet_explorer6.00.2800.1106
windows microsoftinternet_explorer6.0.2900
windows microsoftinternet_explorer6.0.2900.2180
windows microsoftinternet_explorer6.00.2900.2180
windows microsoftinternet_explorer6.00.3663.0000
windows microsoftinternet_explorer6.00.3718.0000
windows microsoftinternet_explorer6.00.3790.0000
windows microsoftinternet_explorer6.00.3790.1830
windows microsoftinternet_explorer6.00.3790.3959
windows microsoftinternet_explorer7
windows microsoftinternet_explorer7.0
windows microsoftinternet_explorer7.0.5730
windows microsoftinternet_explorer7.0.5730.11
windows microsoftinternet_explorer7.00.5730.1100
windows microsoftinternet_explorer7.00.6000.16386
windows microsoftinternet_explorer7.00.6000.16441

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.