{"api_version":"1","generated_at":"2026-07-23T04:57:02+00:00","cve":"CVE-2017-0135","urls":{"html":"https://cve.report/CVE-2017-0135","api":"https://cve.report/api/cve/CVE-2017-0135.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-0135","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-0135"},"summary":{"title":"CVE-2017-0135","description":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.","state":"PUBLISHED","assigner":"microsoft","published_at":"2017-03-17 00:59:03","updated_at":"2025-04-20 01:37:25"},"problem_types":["NVD-CWE-noinfo","Remote Code Execution"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.2","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/96656","name":"http://www.securityfocus.com/bid/96656","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Edge CVE-2017-0135\t Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.freebuf.com/articles/web/164871.html","name":"https://www.freebuf.com/articles/web/164871.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CVE-2017-0135漏洞分析：利用Edge浏览器的XSS过滤器绕过CSP - FreeBuf互联网安全新媒体平台 | 关注黑客与极客","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754","name":"https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bypass CSP by Abusing XSS Filter in Edge – InfoSec Writeups – Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1038006","name":"http://www.securitytracker.com/id/1038006","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Edge Multiple Flaws Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135","name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Update Guide - Microsoft Security Response Center","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-0135","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-0135","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Microsoft Corporation","product":"Edge","version":"affected Edge","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"135","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"edge","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T12:55:18.666Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.freebuf.com/articles/web/164871.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135"},{"name":"1038006","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1038006"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754"},{"name":"96656","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/96656"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Edge","vendor":"Microsoft Corporation","versions":[{"status":"affected","version":"Edge"}]}],"datePublic":"2017-03-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140."}],"problemTypes":[{"descriptions":[{"description":"Remote Code Execution","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-12-03T15:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"tags":["x_refsource_MISC"],"url":"https://www.freebuf.com/articles/web/164871.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135"},{"name":"1038006","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1038006"},{"tags":["x_refsource_MISC"],"url":"https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754"},{"name":"96656","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/96656"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2017-0135","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Edge","version":{"version_data":[{"version_value":"Edge"}]}}]},"vendor_name":"Microsoft Corporation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote Code Execution"}]}]},"references":{"reference_data":[{"name":"https://www.freebuf.com/articles/web/164871.html","refsource":"MISC","url":"https://www.freebuf.com/articles/web/164871.html"},{"name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135","refsource":"CONFIRM","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0135"},{"name":"1038006","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1038006"},{"name":"https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754","refsource":"MISC","url":"https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754"},{"name":"96656","refsource":"BID","url":"http://www.securityfocus.com/bid/96656"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2017-0135","datePublished":"2017-03-17T00:00:00.000Z","dateReserved":"2016-09-09T00:00:00.000Z","dateUpdated":"2024-08-05T12:55:18.666Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-17 00:59:03","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["NVD-CWE-noinfo","Remote Code Execution"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*","matchCriteriaId":"8BD5B232-95EA-4F8E-8C7D-7976877AD243"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"135","Ordinal":"1","Title":"CVE-2017-0135","CVE":"CVE-2017-0135","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"135","Ordinal":"1","NoteData":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.","Type":"Description","Title":"CVE-2017-0135"},{"CveYear":"2017","CveId":"135","Ordinal":"2","NoteData":"2017-03-16","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"135","Ordinal":"3","NoteData":"2018-12-03","Type":"Other","Title":"Modified"}]}}}