| Vulnerability Name: | CVE-2017-0135 (CCN-122446) | ||||||||||||
| Assigned: | 2016-09-09 | ||||||||||||
| Published: | 2017-03-14 | ||||||||||||
| Updated: | 2019-10-03 | ||||||||||||
| Summary: | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140. | ||||||||||||
| CVSS v3 Severity: | 4.2 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N) 3.7 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-0135 Source: CCN Type: Microsoft Security Bulletin MS17-007 Security Update for Microsoft Edge (4013071) Source: BID Type: UNKNOWN 96656 Source: CCN Type: BID-96656 Microsoft Edge CVE-2017-0135 Source: SECTRACK Type: UNKNOWN 1038006 Source: XF Type: UNKNOWN ms-edge-cve20170135-security-bypass(122446) Source: MISC Type: UNKNOWN https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754 Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135 Source: MISC Type: UNKNOWN https://www.freebuf.com/articles/web/164871.html | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||