vendor:
Edge
by:
Skylined
7,5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: Edge
Affected Version From: 11.0.10240.16384
Affected Version To: 11.0.10240.16384
Patch Exists: YES
Related CWE: CVE-2015-6118
CPE: a:microsoft:edge
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Microsoft Edge Memory Corruption Vulnerability
A specially crafted web-page can trigger a memory corruption vulnerability in Microsoft Edge. An attacker would need to get a target user to open a specially crafted web-page. Disabling JavaScript does not prevent an attacker from triggering the vulnerable code path. At the time this issue was first discovered, MemGC was just introduced, and I had not yet fully appreciated what an impact it would have on mitigating use-after-free bugs.
Mitigation:
Microsoft addressed this vulnerability in MS15-125.