CVE-2021-31936HighCVSS 7.4
Microsoft Accessibility Insights for Web Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? This vulnerability could disclose web content from cross-origin frames.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A user would have to visit a web page with malicious javascript and run an extension scan on the web page.
According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? The vulnerability is in the Accessibility Insight for Web browser extension, but the impact is on the application running on the browser.
🎯 Affected products1
- Microsoft Accessibility Insights for Web
✅ Remediation
KBRelease Notes (Security Update) — fixed build 2.26.0