Microsoft Edge SVG Null Pointer Dereference

Strike ID:
E19-0zjy1
CVSS:
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
False Positive:
t
Variants:
6
Year:
2018

Description

This strike exploits a null pointer dereference vulnerability in Microsoft Edge browser. The vulnerability resides in the way the browser's engine handles dynamically created namespacesURI elements. By exploiting the vulnerability an attacker is able to cause denial of service conditions on target's browser.

References