Intrusion Prevention

MS.IE.URL.files.Handling.Security.Bypass

Description

This indicates an attack attempt to exploit a Security Bypass vulnerability in Microsoft Internet Explorer.
The vulnerability is due to an error when the vulnerable software attempts to handles maliciously crafted URL file. An attacker can exploit this to bypass intended Internet Explorer access restrictions via a specially crafted URL file.

Affected Products

Microsoft Internet Explorer 9
Microsoft Internet Explorer 10
Microsoft Internet Explorer 11
Microsoft Internet Explorer 11 on Windows 10

Impact

Security Bypass: Remote attackers can bypass security mechanism on vulnerable systems

Recommended Actions

Apply the most recent upgrade or patch from the vendor
http://technet.microsoft.com/security/bulletin/MS16-104

CVE References

CVE-2016-3353