Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-29354

Опубликовано: 05 мая 2023
Источник: msrc
CVSS3: 4.7
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

FAQ

What is the version information for this release?

Microsoft Edge ChannelMicrosoft Edge VersionBased on Chromium VersionDate Released
Stable113.0.1774.35113.0.5672.63/.645/5/2023
Extended Stable112.0.1722.71112.0.5615.1795/4/2023

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

The user would have to click on a specially crafted URL to be compromised by the attacker.

According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of Integrity (I:L)? What does that mean for this vulnerability?

Attacker is able to bypass Content Security Policy (CSP) and Pop-up blocker this this vulnerability, but cannot modify additional content of the browser itself.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

This vulnerability could lead to a browser iFrame sandbox escape, but not a full browser sandbox escape.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 50%
0.0027
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
почти 3 года назад

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS3: 4.7
github
почти 3 года назад

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS3: 4.7
fstec
почти 3 года назад

Уязвимость браузера Microsoft Edge, связанная с использованием памяти после ее освобождения, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 50%
0.0027
Низкий

4.7 Medium

CVSS3