VDB
CVE-2023-3420
CVE-2023-3420
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund mehrerer Use-after-free-Probleme und einer Typverwechslung in den Komponenten V8, Media und Guest View. Ein entfernter, anonymer Angreifer kann diese Schwachstellen zur Ausführung von beliebigem Code oder möglicherweise für andere, nicht näher beschriebene Auswirkungen ausnutzen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 4.60% · 89.4th percentile
Risk Scores
EPSS Score
4.60%
89.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedora | Fedora Linux | |
| Microsoft | Microsoft Edge | |
| Debian | Debian Linux | |
| Gentoo | Gentoo Linux | |
| Microsoft | Microsoft Edge < 114.0.1823.67 |
Exploit Intelligence
- https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html (circl)
- https://crbug.com/1452137 (circl)
- https://www.debian.org/security/2023/dsa-5440 (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KREKCQTJDVI2AEBG5ECZPSOQXIC2L5XL/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBAHED5YFJPRGSEKNZIYHZBGSVHGEHOH/ (circl)
- https://security.gentoo.org/glsa/202401-34 (circl)
Timeline
- Jun 26, 2023 CVE Published
- Jun 27, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
- Oct 10, 2023 EPSS Score
- Dec 20, 2023 EPSS Score
- Jan 31, 2024 CVE Updated
- Feb 28, 2024 EPSS Score
- Apr 3, 2024 EPSS Score
- Jun 12, 2024 EPSS Score
- Aug 21, 2024 EPSS Score
- Sep 25, 2024 EPSS Score
- Dec 6, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1574.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1574 advisory
- https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://www.debian.org/security/2023/dsa-5440 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-81803bf20b advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-b7efbdc392 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-64db16429d advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-70aa66d8b2 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#june-29-2023 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-9dad7fa701 advisory
- https://security.gentoo.org/glsa/202401-34 advisory