CVE-2018-1025Sensitive Information Exposure in Microsoft Internet Explorer 11

6 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
8.7%
top 7.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 13

Description

An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5microsoft/internet_explorer_1118 versions+17
CVEListV5microsoft/microsoft_edge11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5xph-3pch-mgwr: An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Informatio2022-05-13
CVEList
CVE-2018-1025: An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Informatio2018-05-09

💥Exploits & PoCs

1
Exploit-DB
STOPzilla AntiMalware 6.5.2.59 - Privilege Escalation (1)2018-09-13

📋Vendor Advisories

1
Microsoft
Microsoft Browser Information Disclosure Vulnerability2018-05-08

💬Community

1
Bugzilla
CVE-2018-8804 ImageMagick: double free in WriteEPTImage function in coders/ept.c2018-03-23
CVE-2018-1025 — Sensitive Information Exposure | cvebase