ZDI-CAN-25393: ZDI-25-090: Microsoft Edge UI Misrepresentation Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-21404.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25393?
ZDI-CAN-25393 has been assigned a CVSS rating which reflects its potential impact and severity.
How do I fix ZDI-CAN-25393?
To mitigate ZDI-CAN-25393, ensure your Microsoft Edge is updated to the latest version provided by Microsoft.
What is the impact of ZDI-CAN-25393 on affected systems?
ZDI-CAN-25393 allows remote attackers to execute arbitrary code on affected Microsoft Edge installations.
Does ZDI-CAN-25393 require user interaction to be exploited?
Yes, ZDI-CAN-25393 requires user interaction, as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-25393?
ZDI-CAN-25393 specifically affects Microsoft Edge installations.