#VU100864 Insufficient UI Warning of Dangerous Operations in Microsoft Edge - CVE-2024-49054
Published: November 23, 2024
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper validation of long URLs for a download domain, which leads to the main part of the domain URL being truncated. A remote attacker can trick the victim into downloading potentially dangerous content from an untrusted domain.