CVE-2023-23374
published 2023-02-14CVE-2023-23374: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
PriorityP346high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
1.07%
60.9th percentile
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 110.0.1587.41 | 110.0.1587.41 |
| microsoft | microsoft_edge_for_android | >= 1.0.0 < 110.0.1587.41 | 110.0.1587.41 |
| msrc | microsoft_edge_for_android | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
vendor_msrc8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2023-02-14·CVSS 8.3
CVE-2023-23374 [HIGH] Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: Why is the severity for this CVE rated as Moderate, but the CVSS score is 8.3?
Per our severity guidelines, the amount of user interaction or preconditions required to allow this sort of exploitation downgraded the severity. The CVSS scoring system doesn't allow for this type of nuance.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted
GHSA
GHSA-hxrq-2cv8-6p64: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ghsa_unreviewed·2023-02-14
CVE-2023-23374 [HIGH] GHSA-hxrq-2cv8-6p64: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published