CVE-2018-0998 describes an information disclosure vulnerability in Microsoft Edge's PDF Reader, affecting Microsoft Edge, Windows 10, and Windows Server 2016. This medium-severity vulnerability, with a CVSS score of 4.3, could allow an attacker to disclose information due to improper memory handling, requiring user interaction (e.g., opening a malicious PDF). There is no evidence of active exploitation, nor is public exploit code available, and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.