Lucene search

K
mscveMicrosoftMS:CVE-2018-8469
HistorySep 11, 2018 - 7:00 a.m.

Microsoft Edge Elevation of Privilege Vulnerability

2018-09-1107:00:00
Microsoft
msrc.microsoft.com
15

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

EPSS

0.003

Percentile

72.0%

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser. An attacker who successfully exploited this vulnerability could gain elevated privileges and break out of the Edge AppContainer sandbox.

The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running.

The security update addresses the vulnerability by modifying how Microsoft Edge handles sandboxing.

Affected configurations

Vulners
Node
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep
OR
microsoftedgeRange<2018-Sep

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

EPSS

0.003

Percentile

72.0%