CAPEC-104: Cross Zone Scripting

An attacker is able to cause a victim to load content into their web-browser that bypasses security zone controls and gain access to increased privileges to execute scripting code or other web objects such as unsigned ActiveX controls or applets. This is a privilege elevation attack targeted at zone-based web-browser security.

Severity
High
Likelihood
Medium
11
/ 100
low-risk
Active Threat 9/50 · Minimal
Exploit Availability 2/50 · Minimal