PT-2025-47035 · Microsoft · Edge
Published
2025-11-11
·
Updated
2025-11-20
·
CVE-2025-9317
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge (affected versions not specified)
Description
A security flaw exists in Edge Project files or Edge Offline Cache files. If an attacker gains read access to these files, they could reverse engineer user passwords—either app-native or Active Directory credentials—by applying computational brute-force techniques to weak cryptographic hashes found within these files. The exploitation of this issue could allow an attacker to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edge