CVE-2020-17153
published 2020-12-09CVE-2020-17153: Microsoft Edge for Android Spoofing Vulnerability Microsoft Edge for Android Spoofing Vulnerability
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.06%
79.1th percentile
Microsoft Edge for Android Spoofing Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_edge_for_android | — | — |
| msrc | microsoft_edge_for_android | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
cvelistv54.3MEDIUM
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6x3g-9r6x-fx66: , aka 'Microsoft Edge for Android Spoofing Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2020-17153 [MEDIUM] CWE-20 GHSA-6x3g-9r6x-fx66: , aka 'Microsoft Edge for Android Spoofing Vulnerability'
, aka 'Microsoft Edge for Android Spoofing Vulnerability'.
CVEList
Microsoft Edge for Android Spoofing Vulnerability
cvelistv5·2020-12-09·CVSS 4.3
CVE-2020-17153 [MEDIUM] Microsoft Edge for Android Spoofing Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
Microsoft
Microsoft Edge for Android Spoofing Vulnerability
vendor_msrc·2020-12-08·CVSS 4.3
CVE-2020-17153 [MEDIUM] Microsoft Edge for Android Spoofing Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
FAQ: How could an attacker exploit the vulnerability?
An attacker would have to convince a user to visit a malicious website, typically via an enticement in email or instant message, or by getting them to open an email attachment.
What is the attack vector for this vulnerability?
The attack vector is address bar spoofing. A malicious website could spoof the contents of a URL bar via a specially crafted HTML page's long URL and then use it for a phishing attack.
Microsoft Edge (HTML-based): Microsoft Edge (HTML-based)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-09
Published