Vulnerability Description
An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to the browser when browsing in the context of the Internet Zone, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0233.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Edge | All versions |
References
- http://www.securityfocus.com/bid/98208Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0241PatchVendor Advisory
- http://www.securityfocus.com/bid/98208Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0241PatchVendor Advisory
FAQ
What is CVE-2017-0241?
CVE-2017-0241 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and ac...
How severe is CVE-2017-0241?
CVE-2017-0241 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-0241?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Edge.