VDB
CVE-2021-37975
CVE-2021-37975
PUBLISHED
KEV
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à la confidentialité des données. Google indique avoir connaissance de l'existence d'un code d'exploitation fonctionnel pour les vulnérabilités CVE-2021-37975 et CVE-2021-37976.
EPSS 34.89% · 98.3th percentile
Risk Scores
EPSS Score
34.89%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | ||
| Microsoft | Edge |
Timeline
- Sep 30, 2021 PoC Published
- Oct 1, 2021 CVE Published
- Oct 9, 2021 EPSS Score
- Nov 3, 2021 CISA KEV Added
- Dec 9, 2021 VulnCheck KEV Exploitation
- Dec 15, 2021 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 1, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Jul 28, 2023 EPSS Score
- Oct 5, 2023 EPSS Score
References
- https://cert.ssi.gouv.fr/avis/CERTFR-2021-AVI-743/ advisory
- https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html advisory
- https://cert.ssi.gouv.fr/avis/CERTFR-2021-AVI-749/ advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37975 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37976 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37974 advisory