Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution via Directory Traversal in Microsoft Edge Feedback Log (CVE‑2026‑45495)

A zero‑day in Microsoft Edge’s feedback‑log handling (CVE‑2026‑45495) enables remote code execution after a user visits a malicious page or opens a crafted file. The vulnerability scores 7.5 CVSS and has been patched by Microsoft, but until updates are applied, organizations face elevated risk of endpoint compromise and downstream supply‑chain impact.

LiveThreat™ Intelligence · 📅 June 05, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Remote Code Execution via Directory Traversal in Microsoft Edge Feedback Log (CVE‑2026‑45495)

What It Is — A newly disclosed zero‑day (ZDI‑26‑331) in Microsoft Edge’s feedback‑log handling permits an attacker to traverse directories and execute arbitrary code. The flaw stems from insufficient validation of a user‑supplied path before file operations are performed.

Exploitability — Exploits require user interaction (visiting a malicious page or opening a crafted file). A proof‑of‑concept was demonstrated at Pwn2Own, and the CVSS base score is 7.5 (High). Microsoft has released a patch.

Affected Products — Microsoft Edge (all supported versions at time of disclosure).

TPRM Impact —

  • Edge is a common browser in corporate environments; compromised endpoints can become launch pads for lateral movement.
  • Third‑party SaaS platforms accessed via Edge may inherit the risk, expanding the attack surface across the supply chain.

Recommended Actions —

  • Deploy Microsoft’s security update for CVE‑2026‑45495 immediately on all managed endpoints.
  • Enforce strict web‑filtering and file‑type controls to block untrusted feedback‑log files.
  • Verify that endpoint protection solutions flag attempts to write outside allowed directories.
  • Update incident‑response playbooks to include detection of anomalous Edge processes and file‑system activity.

Source: Zero Day Initiative Advisory ZDI‑26‑331

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-331/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →