Information Disclosure Vulnerability in Microsoft Edge Web Browser
CVE-2020-1242

5.3MEDIUM

Summary

An information disclosure vulnerability in Microsoft Edge occurs due to improper handling of cross-origin requests. An attacker capable of exploiting this vulnerability can gain unauthorized access to sensitive information from another domain, potentially leading to data leaks. Organizations are encouraged to apply the latest security updates provided by Microsoft to mitigate this risk and protect users from potential exploitation.

Affected Version(s)

Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems = unspecified

Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for ARM64-based Systems = unspecified

Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systems = unspecified

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.