CVE-2018-0766 is an information disclosure vulnerability in the Microsoft Edge PDF Reader, affecting Microsoft Windows 10 versions (Gold, 1511, 1607, 1703, 1709) and Windows Server 2016. The flaw stems from how Edge handles objects in memory, potentially allowing an attacker to gain information for further system compromise. Rated Medium (CVSS 4.3), this vulnerability requires user interaction (UI:R) and can be exploited over a network (AV:N), with low attack complexity (AC:L), leading to a low impact on confidentiality (C:L). There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.