5.7
CVE-2023-28261
- EPSS 0.12%
- Veröffentlicht 27.04.2023 19:15:20
- Zuletzt bearbeitet 28.02.2025 20:15:42
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Edge Chromium SwEditionextended_stable Version < 110.0.1587.78
Microsoft ≫ Edge Chromium Version < 111.0.1661.54
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.323 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 5.7 | 1.4 | 4.2 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
| nvd@nist.gov | 5.7 | 1.4 | 4.2 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.