CAPEC-104: Cross Zone Scripting
An attacker is able to cause a victim to load content into their web-browser that bypasses security zone controls and gain access to increased privileges to execute scripting code or other web objects such as unsigned ActiveX controls or applets. This is a privilege elevation attack targeted at zone-based web-browser security.
Severity
High
Likelihood
Medium
11
/ 100
low-risk
Active Threat
9/50 · Minimal
Exploit Availability
2/50 · Minimal