CVE-2018-8325: Infoleak
Published Jul 11, 2018
·Updated
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2018-8324.
Affected Software
4 affected components
Microsoft Edge
Microsoft Windows 10=1803
All of the following
Microsoft Edge
Microsoft Windows 10=1803
Remediation
Event History
Jul 11, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What interaction is required for exploitation?
The CVSS vector indicates that exploitation is network-based, requires no privileges, and has low attack complexity, but it requires user interaction. An attacker would need a user to interact with attacker-controlled content in Microsoft Edge.
2
What is the security impact if exploitation succeeds?
The stated impact is information disclosure with low confidentiality impact. The CVSS vector indicates no integrity or availability impact.
3
Is a fix available?
Yes. The available remediation is to apply the vendor patch for this vulnerability.