According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker would have to send the victim a malicious file that the victim would have to execute. **According to the CVSS metric, user interaction is required (UI:R) and privileges required is high (PR:H). What does that mean for this vulnerability? An authorized attacker with administrator privileges must send a victim a malicious site and convince them to open it.
Lidor B. with Orca Security