CVE-2017-0068Sensitive Information Exposure in Corporation Browser

Severity
6.1MEDIUMNVD
NVD4.3CNA4.3VulnCheck4.3
EPSS
23.1%
top 4.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0065.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5microsoft_corporation/edgeEdge, The RegEx class in the XSS filter in Microsoft Edge+1
CVEListV5microsoft_corporation/browserInternet Explorer 9 through 11 and Edge

Patches

🔴Vulnerability Details

11
GHSA
GHSA-qh2j-hcp8-r23w: The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive informa2022-05-17
GHSA
GHSA-53gv-m53j-xw4v: Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Micro2022-05-17
GHSA
GHSA-322g-5x7j-7fgm: Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerabilit2022-05-17
GHSA
GHSA-33q8-hj9q-xc35: Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Info2022-05-17
GHSA
GHSA-m792-56jx-j3hj: Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information2022-05-17

📋Vendor Advisories

1
Microsoft
Microsoft Edge based on Edge HTML Information Disclosure Vulnerability2017-03-14
CVE-2017-0068 — Sensitive Information Exposure | cvebase