CVE-2024-21337Heap-based Buffer Overflow in Microsoft Edge

Severity
5.2MEDIUMNVD
EPSS
0.9%
top 24.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateJan 12

Description

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:LExploitability: 1.0 | Impact: 3.7

Affected Packages3 packages

NVDmicrosoft/edge_chromium< 120.0.2210.133
CVEListV5microsoft/microsoft_edge1.0.0120.0.2210.133
CVEListV5microsoft/microsoft_edge_extended_stable1.0.0120.0.2210.160

Patches

🔴Vulnerability Details

2
GHSA
GHSA-94xx-ww3x-xh3v: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability2024-01-12
CVEList
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability2024-01-11

📋Vendor Advisories

1
Microsoft
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability2024-01-09
CVE-2024-21337 — Heap-based Buffer Overflow | cvebase