PT-2019-1593 · Microsoft · Edge
Ivan Fratric
·
Published
2019-03-12
·
Updated
2020-08-24
·
CVE-2019-0612
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge (affected versions not specified)
Description
A security feature bypass issue exists due to improper handling of flash objects by the Click2Play protection in Microsoft Edge. This bypass, on its own, does not allow for arbitrary code execution. However, it could potentially be used in conjunction with another vulnerability, such as a remote code execution vulnerability, to enable an attacker to run arbitrary code on a target system. The issue is related to errors in processing Flash objects, which could allow a remote attacker to launch unauthorized Flash content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edge