CVE-2022-24475: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 8.3)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Edge - Chromium
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2022-Apr
- Released
- 2022-04-01
- EPSS Score
- 1.56% (percentile: 81.5%)
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
100.0.1185.29
4/1/2022
100.0.4896.60
Affected Products (1)
Browser
- Microsoft Edge (Chromium-based)
Acknowledgments
<a href="https://www.daviderceg.com/">David Erceg</a>
Revision History
- 2022-04-01: Information published.