CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-49054

Medium Severity
Microsoft
SVRS
30/100

CVSSv3
4.3/10

EPSS
0.00118/1

CVE-2024-49054 is a spoofing vulnerability affecting Microsoft Edge (Chromium-based). This flaw allows attackers to potentially mislead users by displaying deceptive content. Despite its moderate CVSS score of 4.3, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting it is not currently considered a critical threat requiring immediate action. However, the fact that it is tagged as "In The Wild" warrants monitoring. Successful exploitation could lead to phishing attacks or the distribution of misinformation. While the SVRS indicates a lower level of active threat compared to vulnerabilities scoring above 80, security teams should still apply available patches and remain vigilant for any signs of exploitation to protect users from potential deception.

In The Wild
Vendor-advisory
CVSS:3.1
AV:N
AC:L
PR:N
UI:R
S:U
C:N
I:L
A:N
E:U
RL:O
RC:C
2024-11-22

2025-01-30

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-49054 | Microsoft Edge up to 131.0.2903.48 insufficient warning
vuldb.com2025-01-22
CVE-2024-49054 | Microsoft Edge up to 131.0.2903.48 insufficient warning | A vulnerability, which was classified as problematic, was found in Microsoft Edge. This affects an unknown part. The manipulation leads to insufficient ui warning of dangerous operations. This vulnerability is uniquely identified as CVE-2024-49054. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
vuldb.com
rss
forum
news

Social Media

Alhamdulillah! Thrilled to Announce That I Have Achieved My First CVE ID!🔢🏆✨ I am excited to share that I have achieved my very first CVE ID, CVE-2024-49054, from @Microsoft , in collaboration with one of my senior brothers, Sazzad Mahmud Tomal. #Cybersecurity #CVE
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppMicrosoftedge_chromium

References

ReferenceLink
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49054
MICROSOFT EDGE (CHROMIUM-BASED) SPOOFING VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49054

CWE Details

CWE IDCWE NameDescription
CWE-357Insufficient UI Warning of Dangerous OperationsThe user interface provides a warning to a user regarding dangerous or sensitive operations, but the warning is not noticeable enough to warrant attention.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence