VDB
CVE-2023-24892
CVE-2023-24892
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Zu den Ursachen zählen verschiedene Fehler in der Speicherverwaltung, Fehler bei der Durchsetzung von Richtlinien und Sicherheitsmechanismen sowie andere Implementierungsfehler. Ein Angreifer kann dadurch vertrauliche Informationen offenlegen, Sicherheitsmechanismen umgehen, den Benutzer täuschen und nicht näher beschriebene Auswirkungen erzielen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 17.04% · 95.1th percentile
Risk Scores
EPSS Score
17.04%
95.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedora | Fedora Linux | |
| Microsoft | Microsoft Edge | |
| Ubuntu | Ubuntu Linux | |
| Debian | Debian Linux |
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability (circl)
- Microsoft-Edge-(Chromium-based)-Webview2-1.0.1661.34-Spoofing-Vulnerability (local) by nu11secur1ty (coalition_cess)
- Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing Vulnerability (0day-today)
- Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing Vulnerability (0day-today)
Timeline
- Mar 7, 2023 CVE Published
- Mar 15, 2023 EPSS Score
- Apr 10, 2023 PoC Published
- Apr 23, 2023 EPSS Score
- Jul 9, 2023 EPSS Score
- Aug 3, 2023 CVE Updated
- Aug 17, 2023 EPSS Score
- Sep 24, 2023 EPSS Score
- Sep 27, 2023 EPSS Score
- Nov 2, 2023 EPSS Score
- Jan 19, 2024 EPSS Score
- Feb 26, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0595.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0595 advisory
- https://ubuntu.com/security/notices/USN-5949-1 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#march-13-2023 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-015e4d696d advisory
- https://lists.debian.org/debian-security-announce/2023/msg00060.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-06e40bcae5 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- http://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop.html advisory