SB20170314157 - Microsoft Edge Security Feature Bypass Vulnerability
Published: March 14, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Same-origin policy bypass (CVE-ID: CVE-2017-0140)
The disclosed vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to improper handling of HTML elements present in other browser windows. A remote attacker can trick the victim to visit a specially crafted web page, bypass same-origin policy restrictions and gain access to potentially sensitive information located in a separate browser window.
Remediation
Install update from vendor's website.