First published: Tue Jul 11 2017(Updated: )
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8599 has a severity rating of Medium due to the risk of an attacker exploiting the flaw through malicious content.
To fix CVE-2017-8599, ensure you have installed the latest Microsoft Edge updates that address this vulnerability.
CVE-2017-8599 affects Microsoft Edge in Windows 10 versions Gold, 1511, 1607, and 1703.
Yes, CVE-2017-8599 can be exploited remotely by tricking users into loading malicious web pages.
Symptoms of CVE-2017-8599 exploitation may include unexpected browser behavior or unauthorized access to sensitive information.