Vulnerability identifier: #VU98803
Vulnerability risk: Medium
CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-357
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Microsoft Edge
Client/Desktop applications /
Web browsers
Vendor: Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an input validation error when handling untrusted content. A remote attacker can trick the victim into clicking on a specially crafted link and spoof the content of a legitimate website.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Microsoft Edge: 79.0.309.71 - 79.0.3945.130, 83.0.478.37, 84.0.522.40, 86.0.622.43 - 86.0.622.69, 87.0.664.41 - 87.0.664.75, 88.0.705.50 - 88.0.705.81, 89.0.774.45 - 89.0.774.77, 90.0.818.39 - 90.0.818.66, 91.0.864.37 - 91.0.864.71, 92.0.902.55 - 92.0.902.84, 93.0.961.38 - 93.0.961.52, 94.0.992.31 - 94.0.992.58, 95.0.1020.30 - 95.0.1020.53, 96.0.1054.29 - 96.0.1054.75, 97.0.1072.55 - 97.0.1072.76, 98.0.1108.43 - 98.0.1108.92, 99.0.1150.30 - 99.0.1150.55, 100.0.1185.29 - 100.0.1185.60, 101.0.1210.32 - 101.0.1210.53, 102.0.1245.30 - 102.0.1245.62, 103.0.1264.37 - 103.0.1264.77, 104.0.1293.47 - 104.0.1293.91, 105.0.1343.25 - 105.0.1343.53, 106.0.1370.34 - 106.0.1370.86, 107.0.1418.24 - 107.0.1418.62, 108.0.1293.81 - 108.0.1462.95, 109.0.1343.27 - 109.0.1518.140, 110.0.1587.41 - 110.0.1587.78, 111.0.1661.41 - 111.0.1661.62, 112.0.1722.34 - 112.0.1722.84, 113.0.1774.35 - 113.0.1774.57, 114.0.1823.37 - 114.0.1901.183, 115.0.1901.183 - 115.0.1901.203, 116.0.1938.54 - 116.0.1938.98, 117.0.2045.31 - 117.0.2045.60, 118.0.2088.46 - 118.0.2088.122, 119.0.2151.44 - 119.0.2151.97, 120.0.2210.61 - 120.0.2336.0, 121.0.2277.83 - 121.0.2277.128, 122.0.2365.52 - 122.0.2365.120, 123.0.2420.53 - 123.0.2420.97, 124.0.2478.51 - 124.0.2478.131, 125.0.2535.51 - 125.0.2535.92, 126.0.2592.56 - 126.0.2592.137, 127.0.2651.74 - 127.0.2651.105, 128.0.2739.42 - 128.0.2739.113, 129.0.2792.52 - 129.0.2792.89
External links
http://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43580
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.