Spoofing Vulnerability in Microsoft Browsers on Windows Platforms
CVE-2017-8602

6.5MEDIUM

Summary

A spoofing vulnerability exists in Microsoft browsers, which arises from the improper parsing of HTTP content. An attacker exploiting this vulnerability could potentially deceive users by altering the presentation of web content, misleading them regarding the legitimacy of a site. This impact can result in unauthorized actions being taken on behalf of the users, making it crucial for organizations to ensure that they are using patched versions of affected Windows systems.

Affected Version(s)

Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Microsoft IE 11 and Edge

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.