Vulnerability Found in Microsoft Edge Browser
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
This vulnerability allows the attacker to bypass an Edge security feature named Arbitrary Code Guard (ACG), which is designed to prevent attackers from using JavaScript to load into a computer’s memory via Edge.
The attacker needs to have already compromised the browser to be able to execute this vulnerability. This attack allows an attacker to gain a more reliable, remote execution through bypassing sandbox protections.
Remediation steps
Last edited: 17 February 2020 12:57 pm