CVE ID | CVE-2016-0123 |
CVSS SCORE | 6.8, AV:N/AC:M/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Edge |
VULNERABILITY DETAILS |
The vulnerability relates to how Microsoft Edge processes HTML content with absolute positioning. By manipulating a document's elements an attacker can force Microsoft Edge to read memory outside the bounds of an array. An attacker can leverage this vulnerability to execute code under the context of the current process. |
ADDITIONAL DETAILS |
Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://technet.microsoft.com/library/security/MS16-024 |
DISCLOSURE TIMELINE |
|
CREDIT | d81b2a7b317c035a8da11d63122964c2 |