CVE-2019-1413 PUBLISHED CVSS 4.300000190734863 MEDIUM

A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

EPSS 2.23% · 84.4th percentile

Risk Scores

CVSS v2.0
4.300000190734863
EPSS Score
2.23%
84.4th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for x64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for 32-bit Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for ARM64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for ARM64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for 32-bit Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows Server 2019unspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for 32-bit Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for x64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows Server 2016unspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for ARM64-based Systemsunspecified
microsoftedge
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for x64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for ARM64-based Systemsunspecified
MicrosoftMicrosoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for x64-based Systemsunspecified

Timeline

References

Open in Interactive Console →