CVE-2017-8599 is a security feature bypass vulnerability in Microsoft Edge affecting Windows 10 and Windows Server 2016. It allows an attacker to trick a user into loading malicious content due to improper validation of specially crafted documents by Edge's Content Security Policy (CSP). This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack requiring user interaction, with a high impact on integrity. While there is no known active exploitation or public exploit code, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.