VulnerAlert



MICROSOFT
WEBSITE
20-05-2025 21:30

CVE-2019-1054 Vulnerabilidad documentada

5.0 MEDIUM
Tags
#site
#exploit
#web
#lte
#add
#website
#microsoft
#vulnerability
#design
#bypass
#security
#pass
#malicious
#compromise
#allow
#attack
Descripción
A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tagging (MOTW). Failing to set MOTW means a large number Microsoft technologies are bypassed. In web-based attack scenario, an attacker could host malicious website is designed exploit bypass. Alternatively, email or instant message send targeted user specially crafted .url file Additionally, compromised websites accept user-provided content contain However, all cases would have no way force view attacker-controlled content. Instead, convince take action. For example, entice either click link directs attacker's site attachment. The update addresses by correcting how handles tagging.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1054
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1054
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2019-1054
Resultados similares
Coincidentes en almenos en 50% de los tags
04-06-2025 CVE-2025-20286
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure ...
Ver información
04-06-2025 CVE-2020-36603
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not ...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por