CVE-2011-2382

Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.

Published: 2011-06-03 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2011-2382 is rated Moderate Risk (46.1/100): CVSS Medium severity, with high exploitation likelihood (EPSS 19.30%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2011-2382

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 33.88% 19.30% -14.58%
2 2025-09-20 35.00% 33.88% -1.12%
3 2025-03-30 35.00%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2011-2382

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2011-2382

Affected software / configurations for CVE-2011-2382

Vendor Product Version Raw CPE
microsoft ie 9 cpe:2.3:a:microsoft:ie:9:beta:*:*:*:*:*:*
microsoft internet_explorer <= 8 cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*
microsoft internet_explorer 3.0 cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*
microsoft internet_explorer 3.0.1 cpe:2.3:a:microsoft:internet_explorer:3.0.1:*:*:*:*:*:*:*
microsoft internet_explorer 3.0.2 cpe:2.3:a:microsoft:internet_explorer:3.0.2:*:*:*:*:*:*:*
microsoft internet_explorer 3.1 cpe:2.3:a:microsoft:internet_explorer:3.1:*:*:*:*:*:*:*
microsoft internet_explorer 3.2 cpe:2.3:a:microsoft:internet_explorer:3.2:*:*:*:*:*:*:*
microsoft internet_explorer 4.0 cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
microsoft internet_explorer 4.0.1 cpe:2.3:a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*
microsoft internet_explorer 4.0.1 cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp1:*:*:*:*:*:*
microsoft internet_explorer 4.0.1 cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp2:*:*:*:*:*:*
microsoft internet_explorer 4.01 cpe:2.3:a:microsoft:internet_explorer:4.01:*:*:*:*:*:*:*
microsoft internet_explorer 4.1 cpe:2.3:a:microsoft:internet_explorer:4.1:*:*:*:*:*:*:*
microsoft internet_explorer 4.01 cpe:2.3:a:microsoft:internet_explorer:4.01:sp1:*:*:*:*:*:*
microsoft internet_explorer 4.5 cpe:2.3:a:microsoft:internet_explorer:4.5:*:*:*:*:*:*:*
microsoft internet_explorer 4.40.308 cpe:2.3:a:microsoft:internet_explorer:4.40.308:*:*:*:*:*:*:*
microsoft internet_explorer 4.40.520 cpe:2.3:a:microsoft:internet_explorer:4.40.520:*:*:*:*:*:*:*
microsoft internet_explorer 4.70.1155 cpe:2.3:a:microsoft:internet_explorer:4.70.1155:*:*:*:*:*:*:*
microsoft internet_explorer 4.70.1158 cpe:2.3:a:microsoft:internet_explorer:4.70.1158:*:*:*:*:*:*:*
microsoft internet_explorer 4.70.1215 cpe:2.3:a:microsoft:internet_explorer:4.70.1215:*:*:*:*:*:*:*
microsoft internet_explorer 4.70.1300 cpe:2.3:a:microsoft:internet_explorer:4.70.1300:*:*:*:*:*:*:*
microsoft internet_explorer 4.71.544 cpe:2.3:a:microsoft:internet_explorer:4.71.544:*:*:*:*:*:*:*
microsoft internet_explorer 4.71.1008.3 cpe:2.3:a:microsoft:internet_explorer:4.71.1008.3:*:*:*:*:*:*:*
microsoft internet_explorer 4.71.1712.6 cpe:2.3:a:microsoft:internet_explorer:4.71.1712.6:*:*:*:*:*:*:*
microsoft internet_explorer 4.72.2106.8 cpe:2.3:a:microsoft:internet_explorer:4.72.2106.8:*:*:*:*:*:*:*
microsoft internet_explorer 4.72.3110.8 cpe:2.3:a:microsoft:internet_explorer:4.72.3110.8:*:*:*:*:*:*:*
microsoft internet_explorer 4.72.3612.1713 cpe:2.3:a:microsoft:internet_explorer:4.72.3612.1713:*:*:*:*:*:*:*
microsoft internet_explorer 5 cpe:2.3:a:microsoft:internet_explorer:5:*:*:*:*:*:*:*
microsoft internet_explorer 5.0 cpe:2.3:a:microsoft:internet_explorer:5.0:*:*:*:*:*:*:*
microsoft internet_explorer 5.0.1 cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*
microsoft internet_explorer 5.0.1 cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*
microsoft internet_explorer 5.0.1 cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*
microsoft internet_explorer 5.0.1 cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*
microsoft internet_explorer 5.0.1 cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:*
microsoft internet_explorer 5.00.0518.10 cpe:2.3:a:microsoft:internet_explorer:5.00.0518.10:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.0910.1309 cpe:2.3:a:microsoft:internet_explorer:5.00.0910.1309:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2014.0216 cpe:2.3:a:microsoft:internet_explorer:5.00.2014.0216:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2314.1003 cpe:2.3:a:microsoft:internet_explorer:5.00.2314.1003:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2516.1900 cpe:2.3:a:microsoft:internet_explorer:5.00.2516.1900:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2614.3500 cpe:2.3:a:microsoft:internet_explorer:5.00.2614.3500:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2919.800 cpe:2.3:a:microsoft:internet_explorer:5.00.2919.800:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2919.3800 cpe:2.3:a:microsoft:internet_explorer:5.00.2919.3800:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2919.6307 cpe:2.3:a:microsoft:internet_explorer:5.00.2919.6307:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.2920.0000 cpe:2.3:a:microsoft:internet_explorer:5.00.2920.0000:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.3103.1000 cpe:2.3:a:microsoft:internet_explorer:5.00.3103.1000:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.3105.0106 cpe:2.3:a:microsoft:internet_explorer:5.00.3105.0106:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.3314.2101 cpe:2.3:a:microsoft:internet_explorer:5.00.3314.2101:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.3315.1000 cpe:2.3:a:microsoft:internet_explorer:5.00.3315.1000:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.3502.1000 cpe:2.3:a:microsoft:internet_explorer:5.00.3502.1000:*:*:*:*:*:*:*
microsoft internet_explorer 5.00.3700.1000 cpe:2.3:a:microsoft:internet_explorer:5.00.3700.1000:*:*:*:*:*:*:*
microsoft internet_explorer 5.01 cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*
microsoft internet_explorer 5.1 cpe:2.3:a:microsoft:internet_explorer:5.1:*:*:*:*:*:*:*
microsoft internet_explorer 5.01 cpe:2.3:a:microsoft:internet_explorer:5.01:sp1:*:*:*:*:*:*
microsoft internet_explorer 5.01 cpe:2.3:a:microsoft:internet_explorer:5.01:sp2:*:*:*:*:*:*
microsoft internet_explorer 5.01 cpe:2.3:a:microsoft:internet_explorer:5.01:sp3:*:*:*:*:*:*
microsoft internet_explorer 5.01 cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:*
microsoft internet_explorer 5.2.3 cpe:2.3:a:microsoft:internet_explorer:5.2.3:*:*:*:*:*:*:*
microsoft internet_explorer 5.5 cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*
microsoft internet_explorer 5.5 cpe:2.3:a:microsoft:internet_explorer:5.5:preview:*:*:*:*:*:*
microsoft internet_explorer 5.5 cpe:2.3:a:microsoft:internet_explorer:5.5:sp1:*:*:*:*:*:*
microsoft internet_explorer 5.5 cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
microsoft internet_explorer 5.50.3825.1300 cpe:2.3:a:microsoft:internet_explorer:5.50.3825.1300:*:*:*:*:*:*:*
microsoft internet_explorer 5.50.4030.2400 cpe:2.3:a:microsoft:internet_explorer:5.50.4030.2400:*:*:*:*:*:*:*
microsoft internet_explorer 5.50.4134.0100 cpe:2.3:a:microsoft:internet_explorer:5.50.4134.0100:*:*:*:*:*:*:*
microsoft internet_explorer 5.50.4134.0600 cpe:2.3:a:microsoft:internet_explorer:5.50.4134.0600:*:*:*:*:*:*:*
microsoft internet_explorer 5.50.4308.2900 cpe:2.3:a:microsoft:internet_explorer:5.50.4308.2900:*:*:*:*:*:*:*
microsoft internet_explorer 5.50.4522.1800 cpe:2.3:a:microsoft:internet_explorer:5.50.4522.1800:*:*:*:*:*:*:*
microsoft internet_explorer 5.50.4807.2300 cpe:2.3:a:microsoft:internet_explorer:5.50.4807.2300:*:*:*:*:*:*:*
microsoft internet_explorer 6 cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*
microsoft internet_explorer 6 cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*
microsoft internet_explorer 6.0 cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
microsoft internet_explorer 6.00.2462.0000 cpe:2.3:a:microsoft:internet_explorer:6.00.2462.0000:*:*:*:*:*:*:*
microsoft internet_explorer 6.00.2479.0006 cpe:2.3:a:microsoft:internet_explorer:6.00.2479.0006:*:*:*:*:*:*:*
microsoft internet_explorer 6.0.2600 cpe:2.3:a:microsoft:internet_explorer:6.0.2600:*:*:*:*:*:*:*
microsoft internet_explorer 6.00.2600.0000 cpe:2.3:a:microsoft:internet_explorer:6.00.2600.0000:*:*:*:*:*:*:*
microsoft internet_explorer 6.0.2800 cpe:2.3:a:microsoft:internet_explorer:6.0.2800:*:*:*:*:*:*:*
microsoft internet_explorer 6.0.2800.1106 cpe:2.3:a:microsoft:internet_explorer:6.0.2800.1106:*:*:*:*:*:*:*
microsoft internet_explorer 6.00.2800.1106 cpe:2.3:a:microsoft:internet_explorer:6.00.2800.1106:*:*:*:*:*:*:*
microsoft internet_explorer 6.0.2900 cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:*
microsoft internet_explorer 6.0.2900.2180 cpe:2.3:a:microsoft:internet_explorer:6.0.2900.2180:*:*:*:*:*:*:*

References for CVE-2011-2382

cvelogic Threat Intelligence