VDB
CVE-2023-3422
CVE-2023-3422
PUBLISHED
In Google Chrome und Microsoft Edge existieren mehrere Schwachstellen. Die Fehler bestehen aufgrund mehrerer Use-after-free-Probleme und einer Typverwechslung in den Komponenten V8, Media und Guest View. Ein entfernter, anonymer Angreifer kann diese Schwachstellen zur Ausführung von beliebigem Code oder möglicherweise für andere, nicht näher beschriebene Auswirkungen ausnutzen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.20% · 42.2th percentile
Risk Scores
EPSS Score
0.20%
42.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gentoo | Gentoo Linux | |
| Fedora | Fedora Linux | |
| Debian | Debian Linux | |
| Microsoft | Microsoft Edge | |
| Microsoft | Microsoft Edge < 114.0.1823.67 |
Exploit Intelligence
- https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html (circl)
- https://crbug.com/1450397 (circl)
- https://www.debian.org/security/2023/dsa-5440 (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KREKCQTJDVI2AEBG5ECZPSOQXIC2L5XL/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBAHED5YFJPRGSEKNZIYHZBGSVHGEHOH/ (circl)
- https://security.gentoo.org/glsa/202401-34 (circl)
Timeline
- Jun 26, 2023 CVE Published
- Jun 27, 2023 EPSS Score
- Aug 1, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
- Nov 14, 2023 EPSS Score
- Dec 20, 2023 EPSS Score
- Jan 24, 2024 EPSS Score
- Feb 28, 2024 EPSS Score
- Apr 3, 2024 EPSS Score
- May 8, 2024 EPSS Score
- Jul 17, 2024 EPSS Score
- Aug 21, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1574.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1574 advisory
- https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security advisory
- https://www.debian.org/security/2023/dsa-5440 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-81803bf20b advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-b7efbdc392 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-64db16429d advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-70aa66d8b2 advisory
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#june-29-2023 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-9dad7fa701 advisory
- https://security.gentoo.org/glsa/202401-34 advisory