Kaspersky ID:
KLA12176
Detect Date:
05/13/2021
Updated:
01/25/2024

Description

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, spoof user interface, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A use after free vulnerability in Notifications can be exploited to cause denial of service or execute arbitrary code.
  2. A type confusion vulnerability in V8 can be exploited to cause denial of service.
  3. A use after free vulnerability in Tab Strip can be exploited to cause denial of service or execute arbitrary code.
  4. A heap buffer overflow vulnerability in Reader Mode can be exploited to cause denial of service.
  5. A use after free vulnerability in File API can be exploited to cause denial of service or execute arbitrary code.
  6. A security UI vulnerability in Web App Installs can be exploiteed to spoof user interface.
  7. A race condition vulnerability in Aura can be exploited to bypass security restrictions.
  8. An out of bounds read vulnerability in Tab Groups can be exploited to cause denial of service.
  9. A heap buffer overflow vulnerability in History can be exploited to cause denial of service.
  10. An out of bounds write vulnerability in Tab Strip can be exploited to cause denial of service.
  11. An implementation vulnerability in Offline can be exploited to cause denial of service.
  12. A use after free vulnerability in Payments can be exploited to cause denial of service or execute arbitrary code.
  13. A heap buffer overflow vulnerability in Media Feeds can be exploited to cause denial of service.
  14. A use after free vulnerability in Autofill can be exploited to cause denial of service or execute arbitrary code.

Original advisories

Related products

CVE list

  • CVE-2021-30507
    critical
  • CVE-2021-30516
    critical
  • CVE-2021-30519
    critical
  • CVE-2021-30515
    critical
  • CVE-2021-30506
    critical
  • CVE-2021-30514
    critical
  • CVE-2021-30517
    critical
  • CVE-2021-30513
    critical
  • CVE-2021-30518
    critical
  • CVE-2021-30509
    critical
  • CVE-2021-30508
    critical
  • CVE-2021-30512
    critical
  • CVE-2021-30520
    critical
  • CVE-2021-30510
    critical
  • CVE-2021-30511
    critical

KB list

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.