CVE-2021-31936HighCVSS 7.4

Microsoft Accessibility Insights for Web Information Disclosure Vulnerability

Published
May 11, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? This vulnerability could disclose web content from cross-origin frames.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A user would have to visit a web page with malicious javascript and run an extension scan on the web page.

According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? The vulnerability is in the Accessibility Insight for Web browser extension, but the impact is on the application running on the browser.

🎯 Affected products1

  • Microsoft Accessibility Insights for Web

✅ Remediation

KBRelease Notes (Security Update) — fixed build 2.26.0

🔗 References (2)