Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
The vulnerability is classified as CWE-416 (use-after-free), which means the error is related to improper memory management — an object in memory may be used after it has been freed, leading to the possibility of unintended code execution. The attack vector indicates a network scenario (AV:N) requiring user interaction (UI:R), suggesting that the victim must, for example, visit a specially crafted website or open a malicious resource in the browser. The attack does not require any privileges on the attacker's side (PR:N) and has a scope extending beyond the browser context (S:C — Scope Changed).
Successful exploitation of this vulnerability may allow an attacker to obtain elevated privileges on the victim's system, potentially extending beyond the browser sandbox, which could result in compromise of confidentiality, integrity, and availability of data and system resources.
Security patches provided by the vendor should be applied in accordance with the references — detailed information about fixed versions of Microsoft Edge is available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21326. Immediate browser update to the latest available version is recommended.
Microsoft Edge in versions based on the Chromium engine — specific vulnerable versions are indicated in the vendor's references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMicrosoft Edge
APPMicrosoft< 121.0.2277.83
Related vulnerabilities
Integer overflow w Skia w Google Chrome — sandbox escape
Heap buffer overflow w GPU w Google Chrome — sandbox escape
Type Confusion w Microsoft Edge (Chromium) umożliwia zdalne wykonanie kodu
Eskalacja uprawnień w Microsoft Edge (Chromium) — CWE-416 Use-After-Free
Microsoft Edge (Chromium) — Elevation of Privilege przez use-after-free