CVE-2022-33680
published 2022-07-07CVE-2022-33680: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
PriorityP345high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
1.72%
75.0th percentile
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 103.0.1264.44 | 103.0.1264.44 |
| microsoft | microsoft_edge | >= 1.0.0 < 103.0.1264.44 | 103.0.1264.44 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_msrc8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
vendor_msrc·2022-06-14·CVSS 8.3
CVE-2022-33680 [HIGH] Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
FAQ: How could an attacker exploit this vulnerability via the Network?
An attacker could host a specially crafted website designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action, typically by an enticement in an email or instant message, or by getting the user to open an attachment sent through email.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a browser sandbox escape.
GHSA
GHSA-qq3r-4722-jg4h: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-08·CVSS 8.3
CVE-2022-33680 [HIGH] CWE-269 GHSA-qq3r-4722-jg4h: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30192, CVE-2022-33638, CVE-2022-33639.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-07
Published