Vulnerability identifier: #VU15234
Vulnerability risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-20
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Microsoft Edge
Client/Desktop applications /
Web browsers
Vendor: Microsoft
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper handling of requests of different origins by Microsoft Edge. A remote attacker can trick the victim into visiting a specially crafted website, bypass Same-Origin Policy (SOP) restrictions, allow requests that should otherwise be ignored and possibly force the browser to send data that would otherwise be restricted.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Microsoft Edge: All versions
External links
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8530
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.