PT-2017-18498 · Microsoft · Windows 10+1

Published

2017-09-12

·

Updated

2019-10-03

·

CVE-2017-8724

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Edge in Microsoft Windows 10 Version 1703
Description A spoofing issue exists due to the way Microsoft Edge parses HTTP content. This could allow an attacker to trick a user by redirecting them to a specially crafted website, which could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services. To exploit this issue, the user must click a specially crafted URL.
Recommendations For Microsoft Edge in Microsoft Windows 10 Version 1703, consider avoiding clicking on suspicious or specially crafted URLs as a temporary workaround until a patch is available. Restrict access to untrusted websites to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-8724

Affected Products

Edge
Windows 10