CVE-2018-8235: Medium severity Microsoft Edge vulnerability
Published Jun 14, 2018
·Updated
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.
Affected Software
14 affected components
Microsoft Edge
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows Server 2016
All of the following
Microsoft Edge
Any of the following
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows Server 2016
Remediation
Event History
Jun 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Data Sourced
via NVD·12:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attack can be performed over the network without prior privileges, but it requires user interaction. The affected user would need to interact with attacker-supplied content or requests.
2
What impact could successful exploitation have?
Successful exploitation could disclose information because confidentiality impact is rated low. The available data does not indicate integrity or availability impact.
3
How should affected systems be remediated?
A patch is available for Microsoft Edge. Apply the vendor-provided update to address the vulnerability.