Serious bug in fully patched Internet Explorer puts user credentials at risk
Microsoft engineers are working to patch universal XSS vulnerability. — A vulnerability in fully patched versions of Internet Explorer allows attackers to steal login credentials and inject malicious content into users' browsing sessions.