PT-2017-18498 · Microsoft · Windows 10+1
Published
2017-09-12
·
Updated
2019-10-03
·
CVE-2017-8724
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge in Microsoft Windows 10 Version 1703
Description
A spoofing issue exists due to the way Microsoft Edge parses HTTP content. This could allow an attacker to trick a user by redirecting them to a specially crafted website, which could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services. To exploit this issue, the user must click a specially crafted URL.
Recommendations
For Microsoft Edge in Microsoft Windows 10 Version 1703, consider avoiding clicking on suspicious or specially crafted URLs as a temporary workaround until a patch is available. Restrict access to untrusted websites to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Edge
Windows 10