CVE-2024-30041: Microsoft Bing Search Spoofing Vulnerability

Overview

Severity
Medium (CVSS 5.4)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-May
Released
2024-05-14
Last Updated
2024-05-16
EPSS Score
2.45% (percentile: 85.2%)

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker. How do I get the update for Microsoft Bing Search for iOS? Tap the Settings icon Tap the** iTunes & App Store** Turn on AUTOMATIC DOWNLOADS for Apps Alternatively Tap the** App Store** icon Scroll down to find Bing: Chat with AI & GPT-4 Tap the Update button According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site. According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability? Limited information from the victim's browser associated with the vulnerable URL can be sent to the attacker by the malicious code.

Affected Products (1)

Apps

  • Microsoft Bing Search for iOS

Security Updates (1)

Acknowledgments

<a href="https://twitter.com/Windowsrcer"> James Lee</a>

Revision History

  • 2024-05-14: Information published.
  • 2024-05-15: Updated the build numbers. This is an informational update only.
  • 2024-05-16: Updated acknowledgment. This is an informational change only.