Information Disclosure Vulnerability in Microsoft Edge PDF Reader
CVE-2020-1433
6.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Status
- Microsoft Edge (edgehtml-based) On Windows 10 Version 2004 For Arm64-based Systems
- Microsoft Edge (edgehtml-based) On Windows 10 Version 2004 For X64-based Systems
- Microsoft Edge (edgehtml-based) On Windows 10 Version 2004 For 32-bit Systems
- Microsoft Edge (edgehtml-based) On Windows 10 Version 1803 For 32-bit Systems
- Vendor
- CVE Published:
- 14 July 2020
Summary
An information disclosure vulnerability exists in Microsoft Edge's PDF Reader when it improperly manages memory objects. This flaw may allow an attacker to access sensitive information. It underscores the importance of keeping the software updated and applying the latest patches to ensure your system's security.
Affected Version(s)
Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems = unspecified
Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems = unspecified
Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit Systems = unspecified
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved