4.3

CVE-2018-8235

A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Edge Version -
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 10 Version 1607
   Microsoft ≫ Windows 10 Version 1703
   Microsoft ≫ Windows 10 Version 1709
   Microsoft ≫ Windows 10 Version 1803
   Microsoft ≫ Windows Server 2016 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.86% 0.856
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

http://www.securitytracker.com/id/1041097
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/104343
Third Party Advisory
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8235
Patch
Vendor Advisory