CVE-2017-11863 Information
Feb 14, 2021
cve
Description
Microsoft Edge in Microsoft Windows 10 Gold 1511 1607 1703 1709 Windows Server 2016 and Windows Server version 1709 allows an attacker to trick a user into loading a page containing malicious content due to how the Edge Content Security Policy (CSP) validates documents aka \Microsoft Edge Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2017-11872 and CVE-2017-11874.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
http://www.securityfocus.com/bid/101748 http://www.securitytracker.com/id/1039801 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11863
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: