KLA61868
Multiple vulnerabilities in Microsoft Browser

Updated: 11/07/2023
Detect date
?
11/02/2023
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in Side Panel can be exploited to cause denial of service or execute arbitrary code.
  2. Use after free vulnerability in Printing can be exploited to cause denial of service or execute arbitrary code.
  3. Integer overflow vulnerability in USB can be exploited to cause execute arbitrary code and denial of service.
  4. Implementation vulnerability in Payments can be exploited to cause denial of service.
  5. Security UI vulnerability in Picture In Picture can be exploited to spoof user interface.
  6. A remote code execution vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to execute arbitrary code.
  7. Security UI vulnerability in Downloads can be exploited to spoof user interface.
  8. Implementation vulnerability in Downloads can be exploited to cause denial of service.
  9. Implementation vulnerability in WebApp Provider can be exploited to cause denial of service.
  10. Use after free vulnerability in Reading Mode can be exploited to cause denial of service or execute arbitrary code.
  11. A spoofing vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to spoof user interface.
  12. Use after free vulnerability in Profiles can be exploited to cause denial of service or execute arbitrary code.
  13. Data validation vulnerability in USB can be exploited to cause denial of service.
Affected products

Microsoft Edge (Chromium-based)
Microsoft Edge for Android
Microsoft Edge (Chromium-based) Extended Stable

Solution

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)
Microsoft Edge update settings

Original advisories

CVE-2023-5856
CVE-2023-5852
CVE-2023-5849
CVE-2023-5480
CVE-2023-5859
CVE-2023-36022
CVE-2023-5853
CVE-2023-36034
CVE-2023-5851
CVE-2023-5858
CVE-2023-5855
CVE-2023-5850
CVE-2023-36029
CVE-2023-5854
CVE-2023-5482
CVE-2023-5857

Impacts
?
ACE 
[?]

DoS 
[?]

SUI 
[?]
Related products
Microsoft Edge
CVE-IDS
?
CVE-2023-54805.0Warning
CVE-2023-58515.0Warning
CVE-2023-54825.0Warning
CVE-2023-58565.0Warning
CVE-2023-58525.0Warning
CVE-2023-58595.0Warning
CVE-2023-58555.0Warning
CVE-2023-58505.0Warning
CVE-2023-58495.0Warning
CVE-2023-58535.0Warning
CVE-2023-58545.0Warning
CVE-2023-58575.0Warning
CVE-2023-58585.0Warning
CVE-2023-360225.0Warning
CVE-2023-360345.0Warning
CVE-2023-360295.0Warning
Find out the statistics of the vulnerabilities spreading in your region