First published: Tue Jan 10 2017(Updated: )
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge Beta | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0002 is classified as an Elevation of Privilege vulnerability.
To fix CVE-2017-0002, ensure that Microsoft Edge is updated to the latest version.
CVE-2017-0002 exploits a vulnerability that allows remote attackers to bypass the Same Origin Policy.
All versions of Microsoft Edge prior to the security update addressing CVE-2017-0002 are affected.
The potential impacts of CVE-2017-0002 include unauthorized access to sensitive information and the ability to execute malicious actions.