Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-29350

Опубликовано: 05 мая 2023
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

The user would have to click on a specially crafted URL to be compromised by the attacker.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to win a race condition.

According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), integrity (I:H), and (A:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability could lead to a full compromise of the browser.

What is the version information for this release?

Microsoft Edge ChannelMicrosoft Edge VersionBased on Chromium VersionDate Released
Stable113.0.1774.35113.0.5672.63/.645/5/2023
Extended Stable112.0.1722.71112.0.5615.1795/4/2023

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 7.5
github
почти 3 года назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 7.5
fstec
почти 3 года назад

Уязвимость браузера Microsoft Edge, связанная с использованием памяти после ее освобождения, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3