CVE-2018-8234 is an information disclosure vulnerability in Microsoft Edge that allows an attacker to improperly handle objects in memory, potentially revealing sensitive information. This vulnerability affects Microsoft Edge on Windows 10 and Windows Server 2016. With a CVSS score of 4.3 (Medium), it requires user interaction (UI:R) for exploitation, but has low impact on confidentiality (C:L) and no impact on integrity or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB. While there's limited community discussion and media coverage, it was addressed in Microsoft's June 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.