CVE-2018-8470: XSS
Published Sep 13, 2018
·Updated
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Affected Software
12 affected components
Microsoft Internet Explorer=11
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows 8.1
Microsoft Windows Server=2008-r2
Microsoft Windows Server=2012-r2
Microsoft Windows Server=2016
Remediation
Event History
Sep 13, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-8470?
CVE-2018-8470 is classified as a security feature bypass vulnerability.
2
How do I fix CVE-2018-8470?
To fix CVE-2018-8470, users should apply the latest security updates provided by Microsoft for Internet Explorer.
3
Which software is affected by CVE-2018-8470?
CVE-2018-8470 specifically affects Internet Explorer 11.
4
Can CVE-2018-8470 lead to cross-site scripting?
Yes, CVE-2018-8470 allows for a universal cross-site scripting (UXSS) condition.
5
Is there a workaround for CVE-2018-8470?
Currently, the best mitigative approach for CVE-2018-8470 is to implement the recommended security updates from Microsoft.