CVE-2018-8278: Medium severity Microsoft Edge vulnerability
Published Jul 11, 2018
·Updated
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.
Affected Software
4 affected components
Microsoft Edge
Microsoft Windows 10=1803
All of the following
Microsoft Edge
Microsoft Windows 10=1803
Remediation
Event History
Jul 11, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker must get a user to interact with malicious HTML content. The CVSS vector indicates the attack can be delivered over the network and requires no attacker privileges, but user interaction is required.
2
What is the likely impact if exploitation succeeds?
Successful exploitation can allow spoofing and has low confidentiality and integrity impact. Availability impact is not indicated.
3
Is a fix available?
Yes. A patch is available for the affected Microsoft Edge vulnerability.