PT-2017-18437 · Microsoft · Windows Server 2012 R2+8

Published

2017-07-11

·

Updated

2017-07-14

·

CVE-2017-8602

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016
Description A spoofing issue exists due to improper parsing of HTTP content by affected Microsoft browsers. This could allow an attacker to trick a user into visiting a specially crafted website, potentially leading to content spoofing or serving as a pivot for chaining attacks with other web service vulnerabilities. The user must click a specially crafted URL for the exploit to be successful.
Recommendations To resolve the issue, update Microsoft browsers to a version that properly parses HTTP content. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8602

Affected Products

Edge
Internet Explorer
Windows 7
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2008 R2
Windows Server 2012 R2
Windows Server 2016