Microsoft Edge
CVE-2018-8370 — Microsoft Edge Information Disclosure Vulnerability
Executive Summary
A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests. An attacker who has successfully exploited this vulnerability might be able to read privileged data across trust boundaries. In browsing scenarios, an attacker could convince a user to visit a malicious site and leverage the vulnerability to obtain privileged information from the browser process, such as sensitive data from other opened tabs. An attacker could also inject malicious code into advertising networks used by trusted sites or embed malicious code on a compromised, but trusted, site. The update addresses the vulnerability by correcting how the WebAudio Library handles audio requests.
Overview
3.1
CVSS LOW
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
CVSS Vector
ATTACK VECTOR
Network
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged
CONFIDENTIALITY
Low
INTEGRITY
None
AVAILABILITY
None
Temporal Score: 3.1
EPSS Score
0.04573
probability of exploitation in the next 30 days
0.90792 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
11 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems | 4343892 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems | 4343892 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit Systems | 4343887 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for x64-based Systems | 4343887 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1703 for 32-bit Systems | 4343885 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1703 for x64-based Systems | 4343885 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for 32-bit Systems | 4343897 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1709 for x64-based Systems | 4343897 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems | 4343909 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systems | 4343909 (Security Update) |
Important | Information Disclosure | Yes |
| Microsoft Edge (EdgeHTML-based) on Windows Server 2016 | 4343887 (Security Update) |
Low | Information Disclosure | Yes |
Patches
5 patches
| Article | Type | Restart |
|---|---|---|
4343892 |
Security Update | Yes |
4343887 |
Security Update | Yes |
4343885 |
Security Update | Yes |
4343897 |
Security Update | Yes |
4343909 |
Security Update | Yes |
Exploits & PoC
No public exploit or PoC has been linked for this CVE yet. When available, references are sourced from public repositories and may be unverified or non-functional — review carefully before use.
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
None
References
On This Page