Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43844

Опубликовано: 20 дек. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 9.3
EPSS Низкий

Описание

MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirect versions before 0.5.0.1 are vulnerable to Remote Code Execution via specifically crafted URLs. This vulnerability requires user interaction and the acceptance of a prompt. With how MSEdgeRedirect is coded, parameters are impossible to pass to any launched file. However, there are two possible scenarios in which an attacker can do more than a minor annoyance. In Scenario 1 (confirmed), a user visits an attacker controlled webpage; the user is prompted with, and downloads, an executable payload; the user is prompted with, and accepts, the aforementioned crafted URL prompt; and RCE executes the payload the user previously downloaded, if the download path is successfully guessed. In Scenario 2 (not yet confirmed), a user visits an attacked controlled webpage; the user is prompted with, and accepts, the aforementioned crafted URL prompt; and a payload on a remote, attack

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:msedgeredirect_project:msedgeredirect:*:*:*:*:*:*:*:*
Версия до 0.5.0.1 (исключая)

EPSS

Процентиль: 85%
0.02502
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-610

EPSS

Процентиль: 85%
0.02502
Низкий

8.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-610