Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-1329

Опубликовано: 09 июн. 2020
Источник: msrc
EPSS Низкий

Описание

Microsoft Bing Search Spoofing Vulnerability

A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content. An attacker who successfully exploited this vulnerability could trick a user into believing that the user was on a legitimate website. The specially crafted website, when browsed using the app could spoof the URL and serve malicious content.

To exploit the vulnerability, the user must either browse a malicious website with Bing Search App or be redirected to it by the attacker.

The security update addresses the vulnerability by correcting how Microsoft Bing Search for Android displays the site URL.

FAQ

How do I get the update for Bing Search for Android?

  1. Tap the Google Play icon on your home screen.
  2. Swipe in from the left edge of the screen.
  3. Tap My apps & games.
  4. Tap the Update box next to the Bing Search app.

Is there a direct link on the web?

Yes: https://play.google.com/store/apps/details?id=com.microsoft.bing&hl=en_US

Обновления

ПродуктСтатьяОбновление
Microsoft Bing Search for Android

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 92%
0.08134
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'.

github
больше 3 лет назад

A spoofing vulnerability exists when Microsoft Bing Search for Android improperly handles specific HTML content, aka 'Microsoft Bing Search Spoofing Vulnerability'.

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость поисковой системы Microsoft Bing Search for Android, связанная с некорректной обработкой содержимого HTML-страниц, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 92%
0.08134
Низкий