CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-21326

CVSS 9.6v3.1pub. 2024-01-26upd. 2024-11-21

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-416 (use-after-free), which means the error is related to improper memory management — an object in memory may be used after it has been freed, leading to the possibility of unintended code execution. The attack vector indicates a network scenario (AV:N) requiring user interaction (UI:R), suggesting that the victim must, for example, visit a specially crafted website or open a malicious resource in the browser. The attack does not require any privileges on the attacker's side (PR:N) and has a scope extending beyond the browser context (S:C — Scope Changed).

Impact

Successful exploitation of this vulnerability may allow an attacker to obtain elevated privileges on the victim's system, potentially extending beyond the browser sandbox, which could result in compromise of confidentiality, integrity, and availability of data and system resources.

Mitigation & patch

Security patches provided by the vendor should be applied in accordance with the references — detailed information about fixed versions of Microsoft Edge is available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21326. Immediate browser update to the latest available version is recommended.

Who is affected

Microsoft Edge in versions based on the Chromium engine — specific vulnerable versions are indicated in the vendor's references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Microsoft Edge

    APP
    Microsoft
    < 121.0.2277.83
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2023-6345CRITICAL9.6⚠ KEVPL ✓same product

Integer overflow w Skia w Google Chrome — sandbox escape

CVE-2022-4135CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w GPU w Google Chrome — sandbox escape

CVE-2026-58289CRITICAL9.0PL ✓same product

Type Confusion w Microsoft Edge (Chromium) umożliwia zdalne wykonanie kodu

CVE-2023-35618CRITICAL9.6PL ✓same product

Eskalacja uprawnień w Microsoft Edge (Chromium) — CWE-416 Use-After-Free

CVE-2023-36735CRITICAL9.6PL ✓same product

Microsoft Edge (Chromium) — Elevation of Privilege przez use-after-free