PT-2025-47035 · Microsoft · Edge
Publicado
2025-11-11
·
Atualizado
2025-11-20
·
CVE-2025-9317
CVSS v3.1
8.4
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge (affected versions not specified)
Description
A security flaw exists in Edge Project files or Edge Offline Cache files. If an attacker gains read access to these files, they could reverse engineer user passwords—either app-native or Active Directory credentials—by applying computational brute-force techniques to weak cryptographic hashes found within these files. The exploitation of this issue could allow an attacker to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of a Broken Cryptographic Algorithm
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Edge