Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.
Microsoft Edge permite a atacantes remotos obtener información sensible a través de un sitio web manipulado, también conocido como "Microsoft Edge Information Disclosure Vulnerability". Esta vulnerabilidad es distinta de aquellas descritas en CVE-2017-0009, CVE-2017-0017, CVE-2017-0065 y CVE-2017-0068.
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the processing of the filter attribute in CSS. By manipulating a document's elements an attacker can trigger a read past the end of an allocated data structure. An attacker could leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.