Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.
* Microsoft Edge -
* Microsoft Windows 10 -
* Microsoft Windows 10 1511
* Microsoft Windows 8.1
* Microsoft Windows Server 2012 -
* Microsoft Windows Server 2012
This security update resolves vulnerabilities in Microsoft Edge. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Microsoft Edge. An attacker who successfully exploited the vulnerabilities could gain the same user rights as the current user. Customers whose accounts are configured to have fewer user rights on the system could be less impacted than users with administrative user rights.
This security update is rated Critical for Microsoft Edge on Windows 10. For more information, see the Affected Software section.
The update addresses the vulnerabilities by:
Correcting how the Edge Content Security Policy (CSP) validates documents
Modifying how Windows parses .pdf files