Remote Code Execution Vulnerability in Microsoft Edge (Chromium-based)
CVE-2024-38209
7.8HIGH
Summary
A remote code execution vulnerability exists in Microsoft Edge (Chromium-based) that can allow an attacker to execute arbitrary code on the user's device. This vulnerability may be exploited through specially crafted web content, convincing users to visit a maliciously designed site. Proper mitigating measures should be implemented to avoid potential exploitation of this vulnerability. Users are urged to keep their browsers updated and follow security best practices to enhance their defense against such threats. For more details and guidance, refer to the official Microsoft advisory on the vulnerability.
Affected Version(s)
Microsoft Edge (Chromium-based) Unknown 1.0.0 < 128.0.2739.42
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed