CVE-2018-8463 EXPLOIT
7.4
HIGH · CVSS 3.0 · EPSS 15.4% (pctl 97)
Patch early
A public exploit exists.
Description
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469.
Scoring
| CVSS | 7.4 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N |
| EPSS | 15.42% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-09-13 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | edge |
| microsoft | windows 10 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Edge - Sandbox Escape | 2018-09-27 |
References
- http://www.securityfocus.com/bid/105260
- http://www.securitytracker.com/id/1041623
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8463
- https://www.exploit-db.com/exploits/45502/
- http://www.securityfocus.com/bid/105260
- http://www.securitytracker.com/id/1041623
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8463
- https://www.exploit-db.com/exploits/45502/
→ the Explorer · watch your stack · NVD