Microsoft Edge Security Feature Bypass in Windows 10 and Windows Server
CVE-2017-8599
6.5MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 11 July 2017
What is CVE-2017-8599?
A vulnerability in Microsoft Edge allows an attacker to exploit a failure in the Content Security Policy (CSP) validation process. This weakness enables malicious actors to trick users into loading harmful web pages by delivering specially crafted documents. The issue affects various versions of Windows 10, including Gold, 1511, 1607, and 1703, as well as Windows Server 2016, posing a risk to system integrity and user trust.
Affected Version(s)
Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Edge CSP
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved