CVE-2017-0135
Summary
| CVE | CVE-2017-0135 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-17 00:59:03 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140. |
Risk And Classification
Primary CVSS: v3.0 4.2 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Problem Types: NVD-CWE-noinfo | Remote Code Execution
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 4.2 | MEDIUM | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:H/Au:N/C:P/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Microsoft Corporation | Edge | affected Edge | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Edge CVE-2017-0135 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE-2017-0135漏洞分析:利用Edge浏览器的XSS过滤器绕过CSP - FreeBuf互联网安全新媒体平台 | 关注黑客与极客 | af854a3a-2127-422b-91ae-364da2661108 | www.freebuf.com | |
| Bypass CSP by Abusing XSS Filter in Edge – InfoSec Writeups – Medium | af854a3a-2127-422b-91ae-364da2661108 | medium.com | |
| Microsoft Edge Multiple Flaws Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Update Guide - Microsoft Security Response Center | af854a3a-2127-422b-91ae-364da2661108 | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.