CVE-2017-8644: Infoleak
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8652 and CVE-2017-8662.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are affected?
The affected platforms are Microsoft Windows 10 Gold, version 1511, version 1607, version 1703, and Windows Server 2016 when using Microsoft Edge.
What does an attacker need to exploit this issue?
The CVSS vector indicates the attack can be delivered over the network with low attack complexity and no privileges required, but it requires user interaction. Successful exploitation may disclose information, with no stated integrity or availability impact.
Is a fix available?
Yes. A patch is available for this vulnerability.