PT-2024-1491 · Microsoft · Edge
Jun Kokatsu
+1
·
Published
2024-01-30
·
Updated
2024-09-12
·
CVE-2024-21388
6.5
Medium
Base vector | Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Microsoft Edge (Chromium-based) versions prior to 121.0.2277.83
Description:
The issue is related to the exploitation of Microsoft Edge's Marketing API, allowing attackers to covertly install browser extensions without user consent. This could lead to a privilege escalation threat. The vulnerability was actively exploited and has been patched by Microsoft. Users are advised to update to the latest version to ensure a secure browsing experience.
Recommendations:
For versions prior to 121.0.2277.83, update to version 121.0.2277.83 or later to resolve the issue. As a temporary workaround, consider restricting access to the Marketing API until a patch is applied. Avoid using the private API intended for marketing purposes in the affected browser versions.
Exploit
Fix
RCE
Related Identifiers
Affected Products
References · 53
- 🔥 https://github.com/d0rb/CVE-2024-21388⭐ 6 · Exploit
- https://bdu.fstec.ru/vul/2024-00999 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21388 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21388 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-21388 · Security Note
- https://twitter.com/gossy_84/status/1773289679288188987 · Twitter Post
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2024-21388 · Note
- https://twitter.com/TheHackersNews/status/1773613563275276532 · Twitter Post
- https://twitter.com/VulmonFeeds/status/1752412764193112345 · Twitter Post
- https://twitter.com/transilienceai/status/1804880115022635513 · Twitter Post
- https://twitter.com/ohhara_shiojiri/status/1772974989005791626 · Twitter Post
- https://twitter.com/ComputerPunks/status/1752381924457554037 · Twitter Post
- https://twitter.com/autumn_good_35/status/1772997915398852672 · Twitter Post
- https://twitter.com/jvquantum/status/1772970961374957634 · Twitter Post
- https://twitter.com/xvonfers/status/1752404421932126310 · Twitter Post