First published: Thu Sep 13 2018(Updated: )
An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge Beta | ||
Windows 10 | ||
Windows 10 | =1511 | |
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8464 is rated as critical, indicating a significant threat due to its potential for remote code execution.
CVE-2018-8464 allows attackers to execute arbitrary code on a system running an affected version of Microsoft Edge through malicious PDF files.
CVE-2018-8464 impacts all versions of Microsoft Edge prior to the fix, particularly those that handle PDF files improperly.
To mitigate CVE-2018-8464, users should update Microsoft Edge to the latest version available from Microsoft.
Yes, Microsoft has released a patch for CVE-2018-8464 which resolves the vulnerability in Microsoft Edge.