Spoofing Vulnerability in Microsoft Edge (Chromium-based) IE Mode
CVE-2020-1220
6.1MEDIUM
Key Information:
- Vendor
- Microsoft
- Status
- Microsoft Edge (chromium-based) In Ie Mode On Windows 10 Version 1803 For Arm64-based Systems
- Microsoft Edge (chromium-based) In Ie Mode On Windows 10 Version 1803 For 32-bit Systems
- Microsoft Edge (chromium-based) In Ie Mode On Windows 10 Version 1803 For X64-based Systems
- Microsoft Edge (chromium-based) In Ie Mode On Windows 10 Version 1709 For X64-based Systems
- Vendor
- CVE Published:
- 9 June 2020
Summary
A spoofing vulnerability exists in Microsoft Edge (Chromium-based) when operating in IE Mode, allowing attackers to manipulate specific redirects. This flaw may be exploited to mislead users into interacting with malicious sites, jeopardizing data integrity and user safety.
Affected Version(s)
Microsoft Edge (Chromium-based) in IE Mode on Windows 10 for 32-bit Systems = unspecified
Microsoft Edge (Chromium-based) in IE Mode on Windows 10 for x64-based Systems = unspecified
Microsoft Edge (Chromium-based) in IE Mode on Windows 10 Version 1607 for 32-bit Systems = unspecified
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved