CVE-2020-1220

EUVD-2020-12100
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
microsoftedge
-
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 10
(x64, x86)
1607 (x64, x86)
1709 (arm64, x64, x86)
1803 (arm64, x64, x86)
1809 (arm64, x64, x86)
1903 (arm64, x64, x86)
1909 (arm64, x64, x86)
2004 (arm64, x64, x86)
Windows 7
Service Pack 1 (x64, x86)
Service Pack 1 (x64, x86)
Windows 8.1
(x64, x86)
(x64, x86)
Windows RT 8.1
All
Windows Server 2008 R2
Service Pack 1 (x64)
Service Pack 1 (x64)
Windows Server 2012
Standard
Standard
Windows Server 2012 R2
Standard
Standard
Windows Server 2016
Standard
Windows Server 2019
Standard