CVE-2018-8234: Infoleak
Published Jun 14, 2018
·Updated
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0871.
Affected Software
14 affected components
Microsoft Edge
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows Server 2016
All of the following
Microsoft Edge
Any of the following
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows Server 2016
Remediation
Event History
Jun 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Data Sourced
via NVD·12:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires no privileges, and has low attack complexity. However, it requires user interaction, meaning a user would need to interact with attacker-provided content.
2
What is the impact if exploitation succeeds?
Successful exploitation can disclose information from memory. The supplied CVSS metrics indicate low confidentiality impact and no integrity or availability impact.
3
Is a fix available?
Yes. A patch is available for the affected Microsoft Edge software.