Security Feature Bypass in Microsoft Browsers on Multiple Windows Versions
CVE-2017-8592
6.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 11 July 2017
Summary
This vulnerability affects multiple Microsoft browser versions on various Windows operating systems, allowing attackers to bypass security features due to improper handling of redirect requests. This could potentially enable unauthorized actions or data exposure, compromising the integrity of web interactions. Users of affected Windows versions are advised to apply security updates and implement best practices to mitigate potential risks.
Affected Version(s)
Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Microsoft browsers
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved