CVE-2024-21423
published 2024-02-23CVE-2024-21423: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
PriorityP420medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.58%
44.4th percentile
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 122.0.2365.52 | 122.0.2365.52 |
| microsoft | microsoft_edge | >= 1.0.0 < 122.0.2365.52 | 122.0.2365.52 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_msrc4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
vendor_msrc·2024-02-13·CVSS 4.8
CVE-2024-21423 [MEDIUM] CWE-693 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
FAQ:
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
122.0.2365.52
2/23/2024
122.0.6261.57/.58
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition and also to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?
Exploitation of this vulnerability only discloses limited information, no sensitive information can be obta
GHSA
GHSA-h92p-2jv6-wm6r: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
ghsa_unreviewed·2024-02-24
CVE-2024-21423 [MEDIUM] CWE-693 GHSA-h92p-2jv6-wm6r: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-23
Published