#VU13791 Security restrictions bypass in MSR JavaScript Cryptography Library - CVE-2018-8319
Published: July 10, 2018 / Updated: July 10, 2018
MSR JavaScript Cryptography Library
Microsoft
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists in MSR JavaScript Cryptography Library due to incorrect arithmetic computations. A remote unauthenticated attacker can craft a signature, without the need of the corresponding key, and mimic the entity associated with the public/private key pair to bypass security restrictions.