CVE-2017-0135
CVE-2017-0135
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 7.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Mar 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
Affected products
Microsoft Corporation · EdgeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135https://www.freebuf.com/articles/web/164871.htmlhttp://www.securityfocus.com/bid/96656http://www.securitytracker.com/id/1038006