CVE-2023-21720
published 2023-02-14CVE-2023-21720: Microsoft Edge (Chromium-based) Tampering Vulnerability
PriorityP423medium5.3CVSS 3.1
AVNACHPRNUIRSUCNINAH
EPSS
1.22%
65.5th percentile
Microsoft Edge (Chromium-based) Tampering Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 109.0.15.18.78 | 109.0.15.18.78 |
| microsoft | microsoft_edge | >= 1.0.0 < 109.0.15.18.78 | 109.0.15.18.78 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rwj7-xp4r-5r27: Microsoft Edge (Chromium-based) Tampering Vulnerability
ghsa_unreviewed·2023-02-14
CVE-2023-21720 [MEDIUM] GHSA-rwj7-xp4r-5r27: Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Tampering Vulnerability
vendor_msrc·2023-02-14·CVSS 5.3
CVE-2023-21720 [MEDIUM] CWE-126 Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft Edge (Chromium-based) Tampering Vulnerability
FAQ: Why is the severity for this CVE rated as Moderate, but the CVSS score is higher than normal?
Per our severity guidelines, the amount of user interaction or preconditions required to allow this sort of exploitation downgraded the severity, specifically it says, "If a bug requires more than a click, a key press, or several preconditions, the severity will be downgraded". The CVSS scoring system doesn't allow for this type of nuance.
FAQ: How could an attacker exploit this vulnerability via the Network?
An attacker could host a specially crafted website designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website. However, in all cases an attacker would have no way to force a user to v
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published