CVE-2018-0767 is an information disclosure vulnerability in the Microsoft Edge scripting engine, affecting Windows 10 versions (1511, 1607, 1703, 1709) and Windows Server 2016. Rated Medium (CVSS 5.3), it allows an unauthenticated attacker to obtain sensitive information through user interaction (e.g., clicking a malicious link), potentially leading to further system compromise. While not actively exploited in the wild, a public proof-of-concept (EDB-43522) exists, and it has garnered significant community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.