SB2017061328 - Microsoft Edge Security Feature Bypass Vulnerability



SB2017061328 - Microsoft Edge Security Feature Bypass Vulnerability

Published: June 13, 2017

Security Bulletin ID SB2017061328
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security bypass (CVE-ID: CVE-2017-8555)

The vulnerability allows a remote attacker to bypass security restriction on the target system.

The weakness exists due to improper input validation of the Edge Content Security Policy (CSP). A remote attacker can create a specially crafted website containing malicious content, trick the victim into loading it and bypass security restrictions.

Successful exploitation of the vulnerability may result in access to the affected system.




Remediation

Install update from vendor's website.