PT-2024-9305 · Microsoft · Edge

Haifei Li

+2

·

Published

2024-12-05

·

Updated

2025-01-08

·

CVE-2024-49041

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Edge (Chromium-based) versions up to 131.0.2903.63
Description: A spoofing vulnerability exists in Microsoft Edge, which is based on Chromium. The vulnerability may allow a remote attacker to conduct spoofing attacks by exploiting errors in the user interface's representation of information. The issue can cause the UI to perform wrong actions.
Recommendations: For versions up to 131.0.2903.63, upgrade the affected component immediately to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10994
CVE-2024-49041
ZDI-24-1658

Affected Products

Edge