Логотип exploitDog
bind:CVE-2026-21223
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-21223

Количество 4

Количество 4

nvd логотип

CVE-2026-21223

2 месяца назад

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2026-21223

2 месяца назад

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-wfh6-52w8-8gcj

2 месяца назад

Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass.

CVSS3: 5.1
EPSS: Низкий
fstec логотип

BDU:2026-00807

2 месяца назад

Уязвимость метода LaunchUpdateCmdElevatedAndWait привилегированного COM-интерфейса IElevatorEdge браузера Microsoft Edge, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-21223

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

CVSS3: 7.1
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-21223

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS3: 7.1
0%
Низкий
2 месяца назад
github логотип
GHSA-wfh6-52w8-8gcj

Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass.

CVSS3: 5.1
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-00807

Уязвимость метода LaunchUpdateCmdElevatedAndWait привилегированного COM-интерфейса IElevatorEdge браузера Microsoft Edge, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 8.4
0%
Низкий
2 месяца назад

Уязвимостей на страницу