Executive brief
Microsoft Bing is a web-based search engine used to find information and services online. A vulnerability in its user interface could allow an attacker to misrepresent critical information, potentially tricking users into believing they are interacting with a legitimate site or service. This type of spoofing can lead to the unauthorized disclosure of sensitive information if a user is misled by the falsified interface.
Technical details
A vulnerability classified as CWE-451 (User Interface Misrepresentation of Critical Information) exists in Microsoft Bing. The flaw allows a remote, unauthenticated attacker to spoof interface elements over the network, potentially leading to information disclosure. Exploitation requires user interaction, typically involving a victim visiting a malicious link or viewing crafted content that triggers the UI misrepresentation. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting low impact on confidentiality and no impact on integrity or availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Bing
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory