CVE-2024-43566
published 2024-10-17CVE-2024-43566: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.08%
61.3th percentile
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 130.0.2849.46 | 130.0.2849.46 |
| microsoft | microsoft_edge | >= 1.0.0 < 130.0.2849.46 | 130.0.2849.46 |
| msrc | microsoft_edge | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation requires the victim to click a specially crafted/malicious URL, triggering RCE in the Edge renderer process — monitor for suspicious Edge renderer process spawning child processes or unusual network activity following URL navigation. ↗
- →Attack vector is network with required user interaction via a crafted URL — inspect web proxies and email gateways for links targeting Edge-specific URL schemes or triggering Edge navigation. ↗
- ·As of the advisory publication, the vulnerability has not been publicly disclosed or exploited in the wild, reducing immediate urgency but not eliminating risk. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fm2-m976-8x5p: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ghsa_unreviewed·2024-10-18
CVE-2024-43566 [HIGH] CWE-190 GHSA-4fm2-m976-8x5p: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2024-10-08·CVSS 7.5
CVE-2024-43566 [HIGH] CWE-190 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.59
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
Successful exploitation of this vulnerability requires the victim user to click a malicious link so that the attacker can initiate remote code execution on the renderer process.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
Microsoft Ed
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-17
Published