CVE-2017-11863
CVE-2017-11863
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 3.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick a user into loading a page containing malicious content, due to how the Edge Content Security Policy (CSP) validates documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11872 and CVE-2017-11874.
Affected products
Microsoft Corporation · Microsoft EdgeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →