CVE-2017-8599Improper Input Validation in Microsoft Edge ON Windows 10 FOR 32-bit Systems

Severity
6.5MEDIUMNVD
EPSS
16.8%
top 5.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 13

Description

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Patches

🔴Vulnerability Details

1
GHSA
GHSA-fp62-p4f8-v6q7: Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with2022-05-13

📋Vendor Advisories

1
Microsoft
Microsoft Edge Security Feature Bypass Vulnerability2017-07-11

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - July 20172017-07-11