CVE-2023-28301
published 2023-04-11CVE-2023-28301: Microsoft Edge (Chromium-based) Tampering Vulnerability
PriorityP414low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EPSS
0.87%
54.9th percentile
Microsoft Edge (Chromium-based) Tampering Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge | < 112.0.1722.34 | 112.0.1722.34 |
| microsoft | microsoft_edge_for_android | >= 1.0.0 < 112.0.5615.49/50 | 112.0.5615.49/50 |
| msrc | microsoft_edge_for_android | — | — |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_msrc3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p8c7-jh4h-q359: Microsoft Edge (Chromium-based) Tampering Vulnerability
ghsa_unreviewed·2023-04-11
CVE-2023-28301 [MEDIUM] CWE-20 GHSA-p8c7-jh4h-q359: Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Tampering Vulnerability
vendor_msrc·2023-04-11·CVSS 3.7
CVE-2023-28301 [LOW] Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft Edge (Chromium-based) Tampering Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to first prepare the target so that the attacker is on the same network as potential victims.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
112.0.1722.34
4/6/2023
112.0.5615.49/50
Microsoft Edge (Chromium-based): Microsoft Edge (Chromium-based)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Tampering
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remed
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-11
Published