Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A remote code execution vulnerability has been identified in Microsoft Edge (Chromium-based) versions through 150.0.4078.48. This vulnerability arises from improper input validation, which allows an unauthorized attacker to execute code over a network. Exploitation requires user interaction, such as opening a specially crafted file or visiting an attacker-controlled website.
Successful exploitation of this vulnerability could lead to remote code execution on the affected system.
To reproduce this vulnerability, a user must open a specially crafted file from an attacker, which can initiate remote code execution. Alternatively, an attacker could host a malicious website designed to exploit this vulnerability. However, the user would need to be convinced to visit the site, such as through an email or message.
Users can download the security update for this vulnerability from the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.