Threat Encyclopedia

MS.Edge.Flash.Click2Play.Handling.Security.Bypass

description-logoDescription

This indicates an attack attempt to exploit a Security Bypass vulnerability in Microsoft Edge.
The vulnerability is due to an error when the vulnerable software attempts to improperly handle flash objects. An attacker can exploit this to bypass intended Edge access restrictions by tricking a user into visiting a malicious webpage.

affected-products-logoAffected Products

Microsoft Edge on Windows 10 Version 1703 for 32-bit Systems
Microsoft Edge on Windows 10 Version 1703 for x64-based Systems
Microsoft Edge on Windows 10 Version 1709 for 32-bit Systems
Microsoft Edge on Windows 10 Version 1709 for x64-based Systems
Microsoft Edge on Windows 10 Version 1803 for 32-bit Systems
Microsoft Edge on Windows 10 Version 1803 for x64-based Systems
Microsoft Edge on Windows 10 Version 1803 for ARM64-based Systems
Microsoft Edge on Windows 10 Version 1809 for 32-bit Systems
Microsoft Edge on Windows 10 Version 1809 for x64-based Systems
Microsoft Edge on Windows 10 Version 1809 for ARM64-based Systems
Microsoft Edge on Windows Server 2019
Microsoft Edge on Windows 10 Version 1709 for ARM64-based Systems

Impact

Security Bypass: Remote attackers can bypass security mechanism on vulnerable systems

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0612

CVE References

CVE-2019-0612