PT-2017-18454 · Microsoft · Windows 10+1
Shhnjk
·
Published
2017-08-08
·
Updated
2019-10-03
·
CVE-2017-8650
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge in Microsoft Windows 10 version 1703
Description
A security feature bypass issue exists due to Microsoft Edge not properly enforcing same-origin policies. This could allow an attacker to access information from origins outside the current one. To exploit this issue, an attacker would need to trick a user into loading a page or visiting a website.
Recommendations
For Microsoft Edge in Microsoft Windows 10 version 1703, consider restricting access to sensitive information until a proper fix is applied, and ensure users are cautious when loading pages or visiting websites from unknown origins. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edge
Windows 10