CVE-2018-8567

MEDIUM

Microsoft Edge - Privilege Escalation

Title source: llm
STIX 2.1

Description

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105784
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1042107

Scores

CVSS v3 5.4
EPSS 0.0314
EPSS Percentile 86.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

Status published
Products (1)
microsoft/edge
Published Nov 14, 2018
Tracked Since Feb 18, 2026