First published: Tue Jun 09 2020(Updated: )
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Edge (EdgeHTML-based) | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =2004 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1220 has a severity rating assigned by Microsoft using the Common Vulnerability Scoring System (CVSS).
To address CVE-2020-1220, users should update Microsoft Edge to the latest version that includes the patch for this vulnerability.
CVE-2020-1220 impacts Microsoft Edge (Chromium-based) specifically when operating in Internet Explorer Mode.
Yes, CVE-2020-1220 can be exploited by attackers through specially crafted web content that could lead to spoofing.
While the vulnerability exists within Microsoft Edge, users of Windows 10 and other versions should pay attention to updates that may resolve CVE-2020-1220.