#VU101310 Spoofing attack in Microsoft Edge - CVE-2024-49041
Published: December 6, 2024 / Updated: December 13, 2024
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data within the way Microsoft Edge prompts the user after a file is downloaded. A remote attacker can hide the real filename extension misleading the user into believing that the file type is harmless.