Improper input validation in Microsoft Edge - CVE-2018-8530

 

Improper input validation in Microsoft Edge - CVE-2018-8530

Published: October 9, 2018


Vulnerability identifier: #VU15234
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8530
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper handling of requests of different origins by Microsoft Edge. A remote attacker can trick the victim into visiting a specially crafted website, bypass Same-Origin Policy (SOP) restrictions, allow requests that should otherwise be ignored and possibly force the browser to send data that would otherwise be restricted.


Affected software

Microsoft Edge

How to mitigate CVE-2018-8530

Install updates from vendor's website.


External References

Related Security Bulletins