{"api_version":"1","generated_at":"2026-07-23T06:49:55+00:00","cve":"CVE-2017-0140","urls":{"html":"https://cve.report/CVE-2017-0140","api":"https://cve.report/api/cve/CVE-2017-0140.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-0140","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-0140"},"summary":{"title":"CVE-2017-0140","description":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.","state":"PUBLISHED","assigner":"microsoft","published_at":"2017-03-17 00:59:03","updated_at":"2025-04-20 01:37:25"},"problem_types":["NVD-CWE-noinfo","Security Feature Bypass"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.2","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/96653","name":"http://www.securityfocus.com/bid/96653","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Edge CVE-2017-0140 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140","name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Update Guide - Microsoft Security Response Center","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securitytracker.com/id/1038006","name":"http://www.securitytracker.com/id/1038006","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Edge Multiple Flaws Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-0140","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-0140","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Microsoft Corporation","product":"Edge","version":"affected Edge","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"140","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"edge","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T12:55:18.606Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"96653","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/96653"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140"},{"name":"1038006","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1038006"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Edge","vendor":"Microsoft Corporation","versions":[{"status":"affected","version":"Edge"}]}],"datePublic":"2017-03-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135."}],"problemTypes":[{"descriptions":[{"description":"Security Feature Bypass","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-11T09:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"96653","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/96653"},{"tags":["x_refsource_CONFIRM"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140"},{"name":"1038006","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1038006"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2017-0140","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Edge","version":{"version_data":[{"version_value":"Edge"}]}}]},"vendor_name":"Microsoft Corporation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Security Feature Bypass"}]}]},"references":{"reference_data":[{"name":"96653","refsource":"BID","url":"http://www.securityfocus.com/bid/96653"},{"name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140","refsource":"CONFIRM","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0140"},{"name":"1038006","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1038006"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2017-0140","datePublished":"2017-03-17T00:00:00.000Z","dateReserved":"2016-09-09T00:00:00.000Z","dateUpdated":"2024-08-05T12:55:18.606Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-17 00:59:03","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["NVD-CWE-noinfo","Security Feature Bypass"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*","matchCriteriaId":"8BD5B232-95EA-4F8E-8C7D-7976877AD243"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"140","Ordinal":"1","Title":"CVE-2017-0140","CVE":"CVE-2017-0140","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"140","Ordinal":"1","NoteData":"Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka \"Microsoft Edge Security Feature Bypass Vulnerability.\" This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.","Type":"Description","Title":"CVE-2017-0140"},{"CveYear":"2017","CveId":"140","Ordinal":"2","NoteData":"2017-03-16","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"140","Ordinal":"3","NoteData":"2017-07-11","Type":"Other","Title":"Modified"}]}}}