Browser

Authentication & Access Bypass

Microsoft Edge Elevation of Privilege Vulnerability

Microsoft Edge Elevation of Privilege Vulnerability This vulnerability allows an attacker to execute javascript code on every host without the permission, also an attacker can steal local system…

6.8
/ 10
Medium
CVSS v3.0
ADVISORY ID
PS26
PUBLISHED
2022-10-02
CVE IDs
CVE-2019-0678
VENDORS
Microsoft
PUBLIC EXPLOIT
None indexed
CWE
CWE-863
PRODUCT
Microsoft Edge
CVSS VECTOR
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Microsoft Edge Elevation of Privilege Vulnerability

This vulnerability allows an attacker to execute javascript code on every host without the permission, also an attacker can steal local system files, and this also results in changing internal developer settings in Microsoft Edge.

Vulnerability details

Vulnerability details

CVE-2019-0678
CWE-863
Medium | 6.8

Microsoft Edge Elevation of Privilege Vulnerability This vulnerability allows an attacker to execute javascript code on every host without the permission, also an attacker can steal local system files, and this also results in changing internal developer

Auth:
None (remote, user interaction required)
Impact:
Sensitive data disclosure, arbitrary data or code modification
DISCLOSURE

Disclosure timeline

2018-11-28 reported to the vendor

2019-12-03 coordinated public release of advisory

Credits

Nikhil Mittal