Attacker Value
Moderate
(1 user assessed)
Exploitability
High
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
1

Windowsrcer IE/Edge Cross-URL vulnerabilities

Last updated June 02, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Cross-Origin bugs in IE and Edge allow bypassing SOP in both browsers.

0-days released by James Lee @Windowsrcer

Add Assessment

4
Ratings
  • Attacker Value
    Medium
  • Exploitability
    High
Technical Analysis

A SOP bug requires the attacker to inject a resource into one domain, and be listening on another. Such a vulnerability would need to be combined with a web application vulnerability like XSS, and would be less useful from a standalone PoV as something like a Metasploit module. But with the right target audience and web application, this is a nice primitive.

General Information

Additional Info

Technical Analysis