CVE-2017-0065
MEDIUMMicrosoft Edge - Information Disclosure via Crafted Web Site
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0065. PoCs published by Dankirk.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2017-0065, which abuses Microsoft Edge's `read://` URL handler to exfiltrate local files without user consent. The exploit requires a forged HTML file placed in a specific directory and a malicious server to capture the leaked data.
Description
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0068.
Exploits (1)
This repository contains a functional exploit for CVE-2017-0065, which abuses Microsoft Edge's `read://` URL handler to exfiltrate local files without user consent. The exploit requires a forged HTML file placed in a specific directory and a malicious server to capture the leaked data.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N