#VU31684 Insecure DLL loading in Microsoft Edge - CVE-2020-1341
Published: July 20, 2020
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to DLL files are allowed to download without prompting additional warning to the user. A remote attacker can trick a victim to visit a specially crafted website to drop the DLL files on the users Download folder (or equivalent) and gain elevated privileges.