#VU14352 Security restrictions bypass in Microsoft Edge - CVE-2018-8358
Published: August 14, 2018
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to bypass security restrictions on on the target system.
The vulnerability exists due to an error when Microsoft Edge improperly handles redirect requests. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website and bypass Cross-Origin Resource Sharing (CORS) redirect restrictions, follow redirect requests that should otherwise be ignored and force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice.