CVE-2016-0125: Infoleak
Published Mar 9, 2016
·Updated
Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka "Microsoft Edge Information Disclosure Vulnerability."
Affected Software
1 affected component
Microsoft Edge
Event History
Mar 9, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0125?
CVE-2016-0125 has a moderate severity rating due to its potential for information disclosure.
2
How do I fix CVE-2016-0125?
To fix CVE-2016-0125, ensure that you update Microsoft Edge to the latest version provided by Microsoft.
3
What kind of information can be exposed by CVE-2016-0125?
CVE-2016-0125 can potentially expose sensitive browser history and request information through a crafted HTTPS site.
4
Which version of Microsoft Edge is affected by CVE-2016-0125?
All versions of Microsoft Edge prior to the corresponding security update are affected by CVE-2016-0125.
5
Is CVE-2016-0125 a remote attack vulnerability?
Yes, CVE-2016-0125 allows remote attackers to exploit the vulnerability through a crafted web page.