CVE-2023-21796
📛 CVE Title
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Description
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 8.3 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 8.3 / 10 HIGH source: CNA overview
- MSRC score
- 8.3 / 10 HIGH MS rating: Important · Elevation of Privilege
- CWE(s)
- —
- Reserved
- 2022-12-16
- Published
- 2023-01-12 08:00 UTC
- Last updated
- 2023-01-17 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21796.json
- Linked Threat
- CVE-2023-21796 — Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-25963 - Assigner
- microsoft
- Published
- Jan 23, 2023, 12:00:00 AM
- Updated
- Jan 1, 2025, 12:36:16 AM
- EUVD base score (CVSS 3.1)
-
8.3 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 0.6600
- Vendors
- Microsoft
- Products
-
Microsoft Edge (Chromium-based) Extended Stable (1.0.0 <108.0.1462.83)
- Aliases
-
GHSA-jpw8-vg77-hg97
ENISA description: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-12 01:01 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Elevation of Privilege
- MS CVSS base score
- 8.3 / 10 (temporal 7.2)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
- Release
- 2023-Jan
Microsoft remediations / KB articles (1)
- Release Notes — Vendor Fix / Security Update (fixed build 108.0.1462.83)
Microsoft FAQ (3)
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a browser sandbox escape.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft Edge (Chromium-based) Extended Stable |
1.0.0 (affected)
|
Unknown |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (4)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://attackerkb.com/topics/CVE-2023-21796 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-25963 rapid7:euvd.enisa.europa.eu
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21796 rapid7:msrc.microsoft.com
- https://www.cve.org/CVERecord?id=CVE-2023-21796 rapid7:www.cve.org
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-06-04 12:45 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-06-04 12:45 UTC -
web:krebsonsecurity.com
Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.
2026-06-04 12:45 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 12:45 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-06-04 12:45 UTC -
web:www.rapid7.com
Microsoft is publishing 77 vulnerabilities this Patch Tuesday, including two publicly disclosed zero-day vulnerabilities.
2026-06-04 12:45 UTC -
web:www.windowslatest.com
Windows 11 March 2026 Patch Tuesday update adds Emoji 16.0, Sysmon, network speed test, reliability improvements, and security fixes.
2026-06-04 12:45 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-04 12:45 UTC -
web:www.instagram.com
804K Followers, 26 Following, 6,243 Posts - THE FIX (@thefixza) on Instagram: "#DOWHATSRIGHT Shop on Bash.com Tag your OOTD #THEFIXDrip #THEFIXDenimDrip"
2026-05-22 05:46 UTC -
web:www.msn.com
Windows 11 patch fix : Microsoft resolved May 2026 update failures tied to limited EFI partition space with automated rollback, IT admin workarounds, and registry-based adjustments. Exchange flaw ...
2026-05-22 05:46 UTC -
web:www.cnn.com
View Comfort Systems USA, Inc. FIX stock quote prices, financial information, real-time forecasts, and company news from CNN.
2026-05-22 05:46 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-22 05:46 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-22 05:46 UTC -
web:support.microsoft.com
For information about how to apply Mitigation 1 and Mitigation 2 in two separate steps (if you want to be more cautious, at least at first) see KB5025885: How to manage the Windows boot manager revocations for Secure Boot changes associated with CVE - 2023 -24932.
2026-05-22 05:46 UTC -
web:www.callofduty.com
Make sure you're following @CODUpdates, @Treyarch, @RavenSoftware for critical live communications and track common Live Issues on our Trello Boards. For regular updates about all Call of Duty® related live issues, follow @CODUpdates. For updates about Call of Duty®: Black Ops 7 Multiplayer and Zombies, follow @Treyarch. For regular updates about Call of Duty®: Black Ops 7 Campaign and ...
2026-05-22 05:46 UTC -
web:cyberpress.org
Anthropic's Claude Code network sandbox allowed any process inside the sandbox to silently bypass egress restrictions and reach blocked hosts, enabling potential exfiltration of credentials, source code, and environment variables for over five months across roughly 130 published versions.
2026-05-22 05:46 UTC -
web:www.csoonline.com
Consultants see the problem eating away at valuable patch resources because of a lack of Microsoft update hygiene.
2026-05-22 05:46 UTC -
web:www.facebook.com
Concord NH Patch . 44,188 likes · 3,578 talking about this. Hyperlocal news, alerts, discussions and events for Concord, NH
2026-05-22 05:46 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-21796.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:51:50.997Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21796"
},
{
"tags": [
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202311-11"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"platforms": [
"Unknown"
],
"product": "Microsoft Edge (Chromium-based) Extended Stable",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "108.0.1462.83",
"status": "affected",
"version": "1.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:extended_stable:*:*:*",
"versionEndExcluding": "108.0.1462.83",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2023-01-12T08:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Elevation of Privilege",
"lang": "en-US",
"type": "Impact"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-01-01T00:36:16.887Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21796"
}
],
"title": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2023-21796",
"datePublished": "2023-01-23T00:00:00.000Z",
"dateReserved": "2022-12-16T00:00:00.000Z",
"dateUpdated": "2025-01-01T00:36:16.887Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}