vendor:
Edge
by:
Project Zero
7,5
CVSS
HIGH
Out-of-Bound Access
125
CWE
Product Name: Edge
Affected Version From: Microsoft Edge 38.14393.1066.0
Affected Version To: Microsoft EdgeHTML 14.14393
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:edge
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10
2017
Out-of-Bound Access in CInputDateTimeScrollerElement::_SelectValueInternal
The vulnerability has been confirmed on Windows 10 Enterprise 64-bit (OS version 1607, OS build 14393.1198) and Microsoft Edge 38.14393.1066.0, Microsoft EdgeHTML 14.14393. An attacker can put data they control at array+offset, they would be able to call this->_UpdateSelected with a controlled argument, which presumably would be sufficient to turn this into a write primitive.
Mitigation:
Update to the latest version of Microsoft Edge