CVE-2017-8599: Microsoft Edge

Medium severity, CVSS 6.5. EPSS: 5.1% chance of exploitation in the next 30 days.

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".

Affected products

Published 2017-07-11. Last modified 2026-06-17.