Permissions, Privileges, and Access Controls in Microsoft Edge - CVE-2019-1054

 

Permissions, Privileges, and Access Controls in Microsoft Edge - CVE-2019-1054

Published: June 12, 2019


Vulnerability identifier: #VU18767
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1054
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists in Microsoft Edge due to the browser fails to set Mark of the Web Tagging (MOTW). Such browser behavior leads to possibility to bypass a large number of Microsoft security technologies.


Affected software

Microsoft Edge

How to mitigate CVE-2019-1054

Install updates from vendor's website.


External References

Related Security Bulletins