CVE-2016-7204: Infoleak
Published Nov 10, 2016
·Updated
Microsoft Edge allows remote attackers to access arbitrary "My Documents" files via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability."
Affected Software
1 affected component
Microsoft Edge
Event History
Nov 10, 2016
CVE Published
via MITRE·06:16 AM
Data Sourced
via MITRE·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7204?
CVE-2016-7204 is rated as a medium severity vulnerability.
2
How do I fix CVE-2016-7204?
To fix CVE-2016-7204, ensure that you install the latest security updates for Microsoft Edge.
3
What types of attacks does CVE-2016-7204 enable?
CVE-2016-7204 enables remote attackers to access arbitrary files in a user's "My Documents" folder.
4
Which versions of Microsoft Edge are affected by CVE-2016-7204?
All versions of Microsoft Edge prior to the security update addressing CVE-2016-7204 are affected.
5
Can CVE-2016-7204 be exploited without user interaction?
Yes, CVE-2016-7204 can potentially be exploited by a remote attacker through a crafted website without user interaction.