#VU25250 Permissions, Privileges, and Access Controls in Microsoft Edge and Microsoft Internet Explorer - CVE-2020-0706

 

#VU25250 Permissions, Privileges, and Access Controls in Microsoft Edge and Microsoft Internet Explorer - CVE-2020-0706

Published: February 11, 2020


Vulnerability identifier: #VU25250
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2020-0706
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft Edge
Microsoft Internet Explorer
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in the way Microsoft browsers handle cross-origin requests. A remote attacker can create a specially crafted web page, trick the victim into visiting it and determine the origin of all of the web pages in the affected browser.


Remediation

Install updates from vendor's website.

External links