PT-2024-10288 · Microsoft · Edge

Oruga

·

Published

2024-12-11

·

Updated

2025-07-03

·

CVE-2025-21399

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Edge (Chromium-based) (affected versions not specified)
Description The issue concerns an elevation of privilege vulnerability in Microsoft Edge. This vulnerability may allow an attacker to elevate their privileges, potentially leading to unauthorized actions on the system, exposure of sensitive information, and system compromise. No specific details about affected devices or real-world incidents are provided. Technical details about exploitation are not mentioned.
Recommendations Update Microsoft Edge: Immediately apply the latest security patches from Microsoft. Monitor Your Systems: Keep an eye on system logs for any signs of suspicious activity. Strengthen Security Configurations: Ensure your browser's security settings are optimized to fend off threats.

Exploit

Fix

LPE

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2025-00696
CVE-2025-21399

Affected Products

Edge