CVE-2018-0803

low-risk
Published 2018-01-04

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to access information from one domain and inject it into another domain, due to how Microsoft Edge enforces cross-domain policies, aka "Microsoft Edge Elevation of Privilege Vulnerability".

Do I need to act?

~
3.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.2/10 Medium
NETWORK / HIGH complexity

Affected Products (1)

Affected Vendors

26
/ 100
low-risk
Severity 14/34 · Moderate
Exploitability 7/34 · Low
Exposure 5/34 · Minimal