PT-2022-1813 · Microsoft · Edge

David Erceg

·

Published

2022-01-06

·

Updated

2024-11-14

·

CVE-2022-21970

CVSS v2.0

8.3

High

VectorAV:N/AC:M/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Edge (Chromium-based) (affected versions not specified)
Description The issue is related to insufficient access controls in Microsoft Edge, allowing a remote attacker to elevate privileges in the system. This can enable the execution of JavaScript code on every host without permission, theft of local system files, manipulation of actions against the machine, and alteration of internal developer settings in Microsoft Edge.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-01243
CVE-2022-21970

Affected Products

Edge