CVE-2017-8599
MEDIUMMicrosoft Edge - Improper Input Validation
Title source: ruleDescription
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
Scores
CVSS v3
6.5
EPSS
0.1676
EPSS Percentile
94.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (2)
microsoft/edge
Microsoft Corporation/Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016
< Edge CSP
Published
Jul 11, 2017
Tracked Since
Feb 18, 2026