CVE-2017-11872 is a security feature bypass vulnerability in Microsoft Edge affecting Windows 10 (versions 1607, 1703) and Windows Server 2016. It allows an attacker to force the browser to send restricted data to an attacker-chosen website by manipulating redirect requests. With a CVSS score of 6.5 (Medium), this vulnerability requires user interaction and has a high impact on confidentiality, but no impact on integrity or availability. While no public exploit code or active exploitation is reported, its EPSS and FAUCET scores indicate a notable risk, and it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.