CVE-2023-36008Use After Free in Microsoft Edge

CWE-416Use After Free4 documents4 sources
Severity
6.6MEDIUMNVD
EPSS
1.0%
top 23.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16

Description

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:LExploitability: 1.8 | Impact: 4.7

Affected Packages3 packages

NVDmicrosoft/edge_chromium< 119.0.2151.72
CVEListV5microsoft/microsoft_edge1.0.0119.0.2151.72
CVEListV5microsoft/microsoft_edge_extended_stable1.0.0118.0.2088.109

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pcwr-76q4-m2q2: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2023-11-16
CVEList
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2023-11-16

📋Vendor Advisories

1
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2023-11-14
CVE-2023-36008 — Use After Free in Microsoft Edge | cvebase