Permissions, Privileges, and Access Controls in Microsoft Edge and Microsoft Internet Explorer - CVE-2020-0706

 

Permissions, Privileges, and Access Controls in Microsoft Edge and Microsoft Internet Explorer - CVE-2020-0706

Published: February 11, 2020


Vulnerability identifier: #VU25250
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0706
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in the way Microsoft browsers handle cross-origin requests. A remote attacker can create a specially crafted web page, trick the victim into visiting it and determine the origin of all of the web pages in the affected browser.


Affected software

Microsoft Edge
Microsoft Internet Explorer

How to mitigate CVE-2020-0706

Install updates from vendor's website.


External References

Related Security Bulletins