KLA49158
Multiple vulnerabilities in Microsoft Browser

Updated: 05/10/2023
Detect date
?
05/05/2023
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to bypass security restrictions, gain privileges, execute arbitrary code, cause denial of service, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A security feature bypass vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to bypass security restrictions.
  2. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  3. Implementation vulnerability in PictureInPicture can be exploited to cause denial of service.
  4. Implementation vulnerability in Prompts can be exploited to cause denial of service.
  5. Validation of untrusted input vulnerability in Exte can be exploited to cause denial of service.
  6. Implementation vulnerability in CORS can be exploited to cause denial of service.
  7. Implementation vulnerability in Full Screen Mode can be exploited to cause denial of service.
Affected products

Microsoft Edge (Chromium-based)

Solution

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)
Microsoft Edge update settings

Original advisories

CVE-2023-29354
CVE-2023-29350
CVE-2023-2468
CVE-2023-2462
CVE-2023-2460
CVE-2023-2464
CVE-2023-2459
CVE-2023-2467
CVE-2023-2466
CVE-2023-2465
CVE-2023-2463

Impacts
?
ACE 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Edge
CVE-IDS
?
CVE-2023-24605.0Critical
CVE-2023-24625.0Critical
CVE-2023-24675.0Critical
CVE-2023-24645.0Critical
CVE-2023-24655.0Critical
CVE-2023-24665.0Critical
CVE-2023-24635.0Critical
CVE-2023-24595.0Critical
CVE-2023-24685.0Critical
CVE-2023-293545.0Critical
CVE-2023-293505.0Critical
Find out the statistics of the vulnerabilities spreading in your region