An information disclosure vulnerability exists in Microsoft Internet Explorer due to improper handling of specially crafted web content while the print preview is generated. An unauthenticated remote attacker could exploit this vulnerability by enticing a user to visit a specially crafted web page and initiate a print preview. Successful exploitation of this vulnerability could allow an attacker to access sensitive information being viewed in any webpage in the targeted user's browser.
Workaround
- Do not use the Print Preview feature in Internet Explorer
- Set Internet and Local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
- Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone
The information provided herein is on "as is" basis, without warranty of any kind.