CVE-2017-8602
medium
CVSS v3
6.5
CVSS v2
4.3
VIR risk
6.5
Description
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@microsoft.com — https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8602
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| windows | - | not-affected | |
| windows | 1511 | not-affected | |
| windows | 1607 | not-affected | |
| windows | 1703 | not-affected | |
| windows | not-affected | | |
| windows | r2 | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | edge | | |
| microsoft | internet_explorer | 11 | |
References
- http://www.securityfocus.com/bid/99390
- http://www.securitytracker.com/id/1038859
- http://www.securitytracker.com/id/1038860
- https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8602
- http://www.securityfocus.com/bid/99390
- http://www.securitytracker.com/id/1038859
- http://www.securitytracker.com/id/1038860
- https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8602
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.