CVE-2023-36787

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 21, 2023
Updated: Jan 1, 2025
CWE ID 416

Summary

CVE-2023-36787 is an elevation of privilege vulnerability affecting Microsoft Edge browsers based on Chromium. This issue grants attackers local system privileges when exploited, allowing them to install programs, modify data, or create new accounts with administrative rights. Exploitation typically requires the attacker to trick a user into opening a specially crafted webpage, though other methods may also be possible. Affected versions of Microsoft Edge include those based on Chromium versions before the patch. Users are advised to update their browsers as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Edge Chromium

Affected Vendors

  • Microsoft