RULE(RULE ID:711080)

Rule General Information
Release Date: 2017-03-17
Rule Name: WEB-CLIENT Microsoft Edge Document.domain Same Origin Policy Bypass Vulnerability -1 (CVE-2017-0002)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulnerability."
Impact: An attacker can take advantage of the vulnerability to bypass the security policy implemented by the software administrator, and perform unauthorized actions to the target system.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS17-001
SecurityFocusBID:95284
SecurityTrackerID:1037573
Solutions
Microsoft has released a patch MS17-001 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS17-001