Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-21383

Опубликовано: 25 янв. 2024
Источник: msrc
CVSS3: 3.3
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Spoofing Vulnerability

FAQ

What is the version information for this release?

Microsoft Edge ChannelMicrosoft Edge VersionDate ReleasedBased on Chromium Version
Stable121.0.2277.831/25/2024121.0.6167.85/.86
Extended Stable120.0.2210.1601/25/2024120.0.6099.268

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

An attacker must send the user a malicious file and convince them to open it.

According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N), some loss of integrity (I:L) but have no effect on availability (A:N). How could an attacker impact the PDF File Signature?

An attacker could spoof the PDF signature stamp by tricking the user with a forgery when they open a digitally signed PDF and view the visual signature stamp.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 40%
0.00187
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
около 2 лет назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVSS3: 3.3
github
около 2 лет назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVSS3: 3.3
fstec
около 2 лет назад

Уязвимость браузера Microsoft Edge, связанная с ошибками представления информации пользовательским интерфейсом, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 40%
0.00187
Низкий

3.3 Low

CVSS3