First published: Wed Sep 13 2017(Updated: )
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge Spoofing Vulnerability". This CVE ID is unique from CVE-2017-8724.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8735 has a medium severity level due to its potential to lead users to malicious sites based on spoofed content.
To fix CVE-2017-8735, ensure that Microsoft Edge is updated to the latest version where this vulnerability is patched.
CVE-2017-8735 affects Microsoft Edge on Windows 10 versions Gold, 1511, 1607, and 1703, as well as Windows Server 2016.
Yes, an attacker can exploit CVE-2017-8735 remotely by redirecting the user to a specially crafted webpage.
CVE-2017-8735 can enable phishing attacks by tricking users into believing they are visiting a legitimate website.