Input validation error in Microsoft Edge and Microsoft Internet Explorer - CVE-2019-1357
Published: October 8, 2019
Vulnerability details
The vulnerability allows a remote attacker to spoofing attack.
The vulnerability exists due to insufficient validation of browser cookies. A remote attacker can send a specially crafted HTTP response and overwrite a secure cookie with an insecure one. This can be used to construct an attack chain against applications that rely on cookie security.
Affected software
Microsoft Internet Explorer