CVE-2021-43844 describes a Remote Code Execution (RCE) vulnerability in MSEdgeRedirect versions prior to 0.5.0.1, a tool designed to redirect browser traffic. This vulnerability, rated 8.8 HIGH CVSS, requires user interaction to accept a specifically crafted URL prompt, allowing an attacker to execute arbitrary code, potentially leading to full system compromise. While no active exploitation in the wild or public exploit code exists, the vulnerability presents a significant risk if a user is tricked into downloading a payload and then accepting the malicious URL prompt. A patched version (0.5.0.1) is available, and users are advised to update and exercise caution with unexpected web prompts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.0.1CPE matchmatch criteria | cpe:2.3:a:msedgeredirect_project:msedgeredirect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.