Input validation error in Microsoft Internet Explorer and Microsoft Edge - CVE-2019-1357
Published: October 8, 2019
Microsoft Internet Explorer
Microsoft Edge
Detailed vulnerability description
The vulnerability allows a remote attacker to spoofing attack.
The vulnerability exists due to insufficient validation of browser cookies. A remote attacker can send a specially crafted HTTP response and overwrite a secure cookie with an insecure one. This can be used to construct an attack chain against applications that rely on cookie security.