CVE-2023-28261

CVSS 3.1 Score 5.7 of 10 (medium)

Details

Published Apr 27, 2023
Updated: Jan 1, 2025

Summary

CVE-2023-28261 is an elevation of privilege vulnerability affecting Microsoft Edge browsers based on Chromium. An attacker who successfully exploits this flaw can gain administrative privileges on the affected system. The vulnerability lies in the way Microsoft Edge handles certain web content, allowing an attacker to run arbitrary code with higher privileges. Users are advised to update their browsers as soon as possible to mitigate the risk. Exploitation of this vulnerability could lead to significant data loss or unauthorized system access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Edge Chromium

Affected Vendors

  • Microsoft