CVE-2018-0871HighCVSS 4.3

Microsoft Edge Information Disclosure Vulnerability

Published
June 12, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists when Edge improperly marks files. An attacker who successfully exploited this vulnerability could exfiltrate file contents from disk. For an attack to be successful, an attacker must persuade a user to open a malicious website. The security update addresses the vulnerability by properly marking files.

🎯 Affected products6

  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1703 for 32-bit Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1703 for x64-based Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for 32-bit Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for x64-based Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems
  • Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systems

✅ Remediation

KB4284874 (Security Update) KB4284819 (Security Update) KB4284835 (Security Update)

🔗 References (4)