Описание
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
Successful exploitation of this vulnerability requires the victim user to click a malicious link in order for the attacker to initiate remote code execution on the renderer process.
What is the version information for this release?
Microsoft Edge Channel | Microsoft Edge Version | Based on Chromium Version | Date Released |
---|---|---|---|
Stable | CVE-2024-8904, | 129.0.6668.58/.59 | 9/19/2024 |
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Уязвимость браузера Microsoft Edge, связанная с ошибками смешения типов данных, позволяющая нарушителю выполнить произвольный код
EPSS
6.5 Medium
CVSS3