KLA12572
Multiple vulnerabilities in Microsoft Browser

Обновлено: 24/06/2022
Дата обнаружения
23/06/2022
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, gain privileges.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in Base can be exploited to cause denial of service or execute arbitrary code.
  2. Inappropriate implementation vulnerability in Extensions API can be exploited to cause denial of service.
  3. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  4. Type confusion vulnerability in V8 can be exploited to cause denial of service.
  5. Use after free vulnerability in WebApp Provider can be exploited to cause denial of service or execute arbitrary code.
  6. Use after free vulnerability in Interest groups can be exploited to cause denial of service or execute arbitrary code.
  7. Insufficient data validation in URL formatting can be exploited to cause denial of service.
  8. Insufficient policy enforcement in DevTools can be exploited to cause denial of service.
  9. Insufficient policy enforcement in File System API can be exploited to cause denial of service
  10. Use after free vulnerability in Cast UI and Toolbar can be exploited to cause denial of service or execute arbitrary code.
Пораженные продукты

Microsoft Edge (Chromium-based)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2022-2156
CVE-2022-2164
CVE-2022-30192
CVE-2022-2158
CVE-2022-2161
CVE-2022-2157
CVE-2022-2165
CVE-2022-2160
CVE-2022-33638
CVE-2022-2162
CVE-2022-2163
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

PE 
[?]
Связанные продукты
Microsoft Edge
Узнай статистику распространения уязвимостей в твоем регионе