Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A remote code execution vulnerability has been identified in Microsoft Edge (Chromium-based) versions through 150.0.4078.48. This vulnerability arises from improper input validation, which allows an unauthorized attacker to execute code over a network. Exploitation requires user interaction, such as opening a specially crafted file or visiting an attacker-controlled website.
Exploitation of this vulnerability allows for remote code execution, with a significant loss of integrity, as the executed code can manipulate data. There is also a low impact on confidentiality and availability, as the vulnerability could be exploited to access data and disrupt services, but at a limited level.
Users can download the security update for this vulnerability through the Microsoft Update Catalog. For more information, see the release notes on the Microsoft Edge update guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.