← All CVEs

CVE-2017-8555

medium · 4.3

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8523 and CVE-2017-8530.

4.3
CVSS
12.5%
EPSS (exploit prob.)
96th
EPSS percentile
2017-06-15
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftedgeall versions
microsoftwindows_101703

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-8555