The flaw, which allows a malicious website to extract user passwords, is made worse if a user is logged in with a Microsoft account.
A previously disclosed flaw in Windows can allow an attacker to steal usernames and passwords of any signed-in user -- simply by tricking a user into visiting a malicious website.