The vulnerability is known as a Universal Cross Site Scripting (XSS) flaw. It allows attackers to bypass the Same-Origin Policy, a browser security mechanism, in order to launch highly credible phishing attacks or hijack users’ accounts on any website. Microsoft is working on a fix for the bug, which works successfully on its Internet Explorer 11 running on both Windows 7 and Windows 8.1 operating systems. The attack also works if the targeted site uses encrypted HTTPS protocol for secure communication.
Source: https://thehackernews.com/2015/02/internet-explorer-xss.html