CVE-2018-8325 is an information disclosure vulnerability in Microsoft Edge, affecting both the browser and Windows 10, caused by improper memory handling. It has a medium severity CVSS score of 4.3, indicating a low impact on confidentiality with no integrity or availability impact, requiring user interaction for exploitation over a network. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, suggesting no active exploitation. Community discussion and media coverage are minimal, with only one article from BleepingComputer mentioning it as part of a larger patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.