Searching
..

Click anywhere to stop

KLA12572
Multiple vulnerabilities in Microsoft Browser

Updated: 01/25/2024
Detect date
?
06/23/2022
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, gain privileges.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in Base can be exploited to cause denial of service or execute arbitrary code.
  2. Inappropriate implementation vulnerability in Extensions API can be exploited to cause denial of service.
  3. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  4. Type confusion vulnerability in V8 can be exploited to cause denial of service.
  5. Use after free vulnerability in WebApp Provider can be exploited to cause denial of service or execute arbitrary code.
  6. Use after free vulnerability in Interest groups can be exploited to cause denial of service or execute arbitrary code.
  7. Insufficient data validation in URL formatting can be exploited to cause denial of service.
  8. Insufficient policy enforcement in DevTools can be exploited to cause denial of service.
  9. Insufficient policy enforcement in File System API can be exploited to cause denial of service
  10. Use after free vulnerability in Cast UI and Toolbar can be exploited to cause denial of service or execute arbitrary code.
Affected products

Microsoft Edge (Chromium-based)

Solution

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)
Microsoft Edge update settings

Original advisories

CVE-2022-2156
CVE-2022-2164
CVE-2022-30192
CVE-2022-2158
CVE-2022-2161
CVE-2022-2157
CVE-2022-2165
CVE-2022-2160
CVE-2022-33638
CVE-2022-2162
CVE-2022-2163

Impacts
?
ACE 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Edge
CVE-IDS
?
CVE-2022-21606.5High
CVE-2022-21646.3High
CVE-2022-21654.3Warning
CVE-2022-21588.8Critical
CVE-2022-21638.8Critical
CVE-2022-21578.8Critical
CVE-2022-21568.8Critical
CVE-2022-21628.8Critical
CVE-2022-21618.8Critical
CVE-2022-301928.3Critical
CVE-2022-336388.3Critical
Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region