Skip to main content

Vulnerability Found in Microsoft Edge Browser

A vulnerability has been discovered in Microsoft Edge that allows an attacker to execute JavaScript on the user’s device and the ability to predict memory space usages.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability has been discovered in Microsoft Edge that allows an attacker to execute JavaScript on the user’s device and the ability to predict memory space usages.

Affected platforms

The following platforms are known to be affected:

Threat details

This vulnerability allows the attacker to bypass an Edge security feature named Arbitrary Code Guard (ACG), which is designed to prevent attackers from using JavaScript to load into a computer’s memory via Edge.

The attacker needs to have already compromised the browser to be able to execute this vulnerability. This attack allows an attacker to gain a more reliable, remote execution through bypassing sandbox protections.


Remediation steps

Type Step
  • Ensure that patches are apply as soon as they become available.
  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts.

Last edited: 17 February 2020 12:57 pm