CVE-2017-8503Cross-site Scripting in Corporation Microsoft Edge

Severity
8.8HIGHNVD
NVD6.1
EPSS
1.2%
top 21.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 17

Description

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pmjq-9rhw-g9xw: Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to elevate privileges due to the way that Microsoft Edge validates JavaScript under spe2022-05-17
GHSA
GHSA-cfph-3c74-3hcj: Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Micr2022-05-13

📋Vendor Advisories

1
Microsoft
Microsoft Edge Elevation of Privilege Vulnerability2017-08-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - August 20172017-08-08
Talos
Microsoft Patch Tuesday - August 20172017-08-08
CVE-2017-8503 — Cross-site Scripting | cvebase