CVE-2018-0771

Description

Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows a security feature bypass, due to how Edge handles different-origin requests, aka Microsoft Edge Security Feature Bypass.

Risk Information

Base Score
2.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
11.213

Associated Vulnerability

VulnerabilityOS Platform
Windows Scripting Engine Memory Corruption Vulnerability for Windows Server 2016 for x64-based Systems - Meltdown and Spectre (KB4074590) - CumulativeWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x64-based Systems - Meltdown and Spectre(KB4074590) - CumulativeWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows Server 2016 for x64-based Systems - Meltdown and Spectre(KB4074590) - DeltaWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x64-based Systems - Meltdown and Spectre (KB4074590) - DeltaWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x86-based Systems - Meltdown and Spectre(KB4074590) - CumulativeWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x86-based Systems - Meltdown and Spectre(KB4074590) - DeltaWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems - Meltdown and Spectre(KB4074592) - CumulativeWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems - Meltdown and Spectre (KB4074592) - DeltaWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems - Meltdown and Spectre(KB4074592) - CumulativeWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems - Meltdown and Spectre(KB4074592) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4088776) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4088776) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4088776) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4088776) - DeltaWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x86-based Systems - Meltdown and Spectre(KB4074590) - CumulativeWindows
Windows Scripting Engine Memory Corruption Vulnerability for Windows 10 Version 1607 for x64-based Systems - Meltdown and Spectre(KB4074590) - CumulativeWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-238512018-02 Cumulative Update for Windows Server 2016 for x64-based Systems - Meltdown and Spectre (KB4074590)
PATCH-238482018-02 Cumulative Update for Windows 10 Version 1607 for x64-based Systems - Meltdown and Spectre(KB4074590)
PATCH-238522018-02 Delta Update for Windows Server 2016 for x64-based Systems - Meltdown and Spectre(KB4074590)
PATCH-238502018-02 Delta Update for Windows 10 Version 1607 for x64-based Systems - Meltdown and Spectre (KB4074590)
PATCH-238472018-02 Cumulative Update for Windows 10 Version 1607 for x86-based Systems - Meltdown and Spectre(KB4074590)
PATCH-238492018-02 Delta Update for Windows 10 Version 1607 for x86-based Systems - Meltdown and Spectre(KB4074590)
PATCH-241002018-03 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4088776)
PATCH-241012018-03 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4088776)
PATCH-241022018-03 Delta Update for Windows 10 Version 1709 for x86-based Systems (KB4088776)
PATCH-241032018-03 Delta Update for Windows 10 Version 1709 for x64-based Systems (KB4088776)
PATCH-238612018-02 Cumulative Update for Windows 10 Version 1607 for x86-based Systems - Meltdown and Spectre(KB4074590)
PATCH-239892018-02 Cumulative Update for Windows 10 Version 1607 for x64-based Systems - Meltdown and Spectre(KB4074590)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234