{"id":33637,"date":"2024-03-30T00:02:25","date_gmt":"2024-03-29T23:02:25","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=33637"},"modified":"2024-03-29T06:47:25","modified_gmt":"2024-03-29T05:47:25","slug":"microsoft-edge-bug-cve-2024-21388-erlaubte-beliebiger-erweiterungen-zu-installieren","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/03\/30\/microsoft-edge-bug-cve-2024-21388-erlaubte-beliebiger-erweiterungen-zu-installieren\/","title":{"rendered":"Microsoft Edge Bug CVE-2024-21388 allowed to install arbitrary extensions"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Edge\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2020\/01\/Edge.jpg\" alt=\"Edge\" width=\"65\" height=\"67\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/03\/28\/microsoft-edge-bug-cve-2024-21388-erlaubte-bsartige-erweiterungen-zu-installieren\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]A now-patched vulnerability in the Microsoft Edge web browser could have been abused to install arbitrary extensions on users' systems and carry out malicious actions. This was revealed by a security researcher to The Hacker News.<\/p>\n<p><!--more--><\/p>\n<h2>CVE-2024-21388 in Edge<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg06.met.vgwort.de\/na\/ba953ac601c742dd80dff6dac922ee90\" alt=\"\" width=\"1\" height=\"1\" \/>The Hacker News reportet in <a href=\"https:\/\/thehackernews.com\/2024\/03\/microsoft-edge-bug-could-have-allowed.html\" target=\"_blank\" rel=\"noopener\">this article<\/a> on information published <a href=\"https:\/\/labs.guard.io\/cve-2024-21388-microsoft-edges-marketing-api-exploited-for-covert-extension-installation-879fe5ad35ca\" target=\"_blank\" rel=\"noopener\">here<\/a>\u00a0by Guardio Labs security researcher Oleg Zaytsev. In a nutshell, a vulnerability in the Edge API allowed any attacker with a method to execute JavaScript on bing.com or microsoft.com pages to install arbitrary extensions from the Edge Add-ons Store without the user's consent or interaction. This is an \"Elevation of Privilege\" issue that has been classified as moderately severe by the Microsoft Security Response Center (MSRC) (CVSS score: 6.5).<\/p>\n<p><img decoding=\"async\" title=\"CVE-2024-21388 im Edge\" src=\"https:\/\/i.postimg.cc\/ZKxdL3LK\/image.png\" alt=\"CVE-2024-21388 im Edge\" \/><br \/>\nCVE-2024-21388 in Edge, Quelle Guardio Labs<\/p>\n<p>The security researchers informed Microsoft about this problem in November 2023. Microsoft closed the vulnerability in Edge at the beginning of February 2024 with security updates and assigned the CVE code CVE-2024-21388.<\/p>\n<p>\"This vulnerability could have allowed an attacker to exploit a private API, originally intended for marketing purposes, to secretly install additional browser extensions with far-reaching permissions without the user's knowledge,\" The Hacker News quotes security researcher Oleg Zaytsev of Guardio Labs.<\/p>\n<p>The vulnerability CVE-2024-21388 (CVSS score: 6.5) was fixed by Microsoft in Edge Stable version 121.0.2277.83 &#8211; the release took place on January 25, 2024. Microsoft confirmed in the release notes that an attacker who successfully exploited this vulnerability could obtain the necessary rights to install an extension. This would make it possible to break out of the browser sandbox.<\/p>\n<p>In <a href=\"https:\/\/www.borncity.com\/blog\/2024\/03\/27\/google-chrome-123-0-6312-86-87\/#comment-177788\" target=\"_blank\" rel=\"noopener\">this German comment<\/a>, a user wrote that Google Chrome (and other browsers) must be pretty garbage if critical security vulnerabilities have been found practically every week for years. I had pointed out that this is topped by Microsoft with Edge. This is because the Chromium engine with all its bugs and vulnerabilities is being used, 'improved' by\u00a0 Microsoft with some stuff and enriched with other things such as Adobe Acrobat in the near future.<\/p>\n<p>And when I read above that the vulnerable private AP was originally intended for marketing purposes, it makes me really happy. There are evil tongues that claim that those who rely on Microsoft and Edge have lost control of their lives. I thought that was a polemic, but I'm slowly starting to \"recognize that's the truth\".<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]A now-patched vulnerability in the Microsoft Edge web browser could have been abused to install arbitrary extensions on users' systems and carry out malicious actions. This was revealed by a security researcher to The Hacker News.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[872,463,580],"tags":[320,69],"class_list":["post-33637","post","type-post","status-publish","format-standard","hentry","category-browser","category-issue","category-security","tag-edge","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33637","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=33637"}],"version-history":[{"count":4,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33637\/revisions"}],"predecessor-version":[{"id":33641,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33637\/revisions\/33641"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=33637"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=33637"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=33637"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}