PT-2017-1465 · Microsoft · Edge+1

Published

2017-03-14

·

Updated

2017-07-12

·

CVE-2017-0012

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Edge versions (affected versions not specified) Microsoft Internet Explorer versions (affected versions not specified)
Description The issue exists due to insufficient input validation in Microsoft browsers, allowing a remote attacker to bypass certificate validation using a specially crafted website. An attacker could exploit this to trick a user by redirecting them to a specially crafted website, which could spoof content or be used to chain an attack with other vulnerabilities in web services. To exploit this, the user must click a specially crafted URL.
Recommendations For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Microsoft Internet Explorer, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00605
CVE-2017-0012

Affected Products

Edge
Internet Explorer