Could the malicious web site operator add new cookies?
Yes. It would be possible for a malicious web site operator to add a cookie that ostensibly belongs to another site. What does the patch do? The patch restores the expected operation to the IE security model, and prevents any web site from viewing another site’s cookie. “Frame Domain Verification” Vulnerability: Frequently Asked Questions: What’s the scope of the vulnerability? The vulnerability could allow a malicious web site operator to view files on the computer of visiting user. The malicious web site operator would need to know the name and location of the file on the user’s computer, and could only view files that can be opened in a browser window. The vulnerability requires Active Scripting in order to succeed. If the malicious site were in a Security Zone that does not allow Active Scripting, the vulnerability could not be exploited. What causes the vulnerability? The vulnerability exists because it is possible, under very specific conditions, to violate IE’s cross-domain secu