vendor:
Edge
by:
Project Zero
8,8
CVSS
HIGH
Type Confusion
843
CWE
Product Name: Edge
Affected Version From: Microsoft Edge 40.15063.0.0 (Insider Preview)
Affected Version To: Microsoft Edge 40.15063.0.0 (Insider Preview)
Patch Exists: Yes
Related CWE: N/A
CPE: a:microsoft:edge
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Microsoft Edge Type Confusion Vulnerability
This vulnerability is a type confusion vulnerability in Microsoft Edge. It occurs when the function 'func(a, b, i)' is replaced with 'func(a, b, {})'. This allows an attacker to create a type confusion between an array and an object, which can be used to corrupt memory and potentially execute arbitrary code. The vulnerability was tested on Microsoft Edge 40.15063.0.0 (Insider Preview).
Mitigation:
Microsoft has released a patch for this vulnerability.