Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
2017-07-11T21:29:02.000
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | edge | * | Yes |
Operating System | microsoft | windows_10 | - | No |
Operating System | microsoft | windows_10 | 1511 | No |
Operating System | microsoft | windows_10 | 1607 | No |
Operating System | microsoft | windows_10 | 1703 | No |
Operating System | microsoft | windows_server_2016 | * | No |