KLA12572
Multiple vulnerabilities in Microsoft Browser

Обновлено: 29/09/2023
Дата обнаружения
23/06/2022
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, gain privileges.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in Base can be exploited to cause denial of service or execute arbitrary code.
  2. Inappropriate implementation vulnerability in Extensions API can be exploited to cause denial of service.
  3. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  4. Type confusion vulnerability in V8 can be exploited to cause denial of service.
  5. Use after free vulnerability in WebApp Provider can be exploited to cause denial of service or execute arbitrary code.
  6. Use after free vulnerability in Interest groups can be exploited to cause denial of service or execute arbitrary code.
  7. Insufficient data validation in URL formatting can be exploited to cause denial of service.
  8. Insufficient policy enforcement in DevTools can be exploited to cause denial of service.
  9. Insufficient policy enforcement in File System API can be exploited to cause denial of service
  10. Use after free vulnerability in Cast UI and Toolbar can be exploited to cause denial of service or execute arbitrary code.
Пораженные продукты

Microsoft Edge (Chromium-based)

Решение

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)
Microsoft Edge update settings

Первичный источник обнаружения
CVE-2022-2156
CVE-2022-2164
CVE-2022-30192
CVE-2022-2158
CVE-2022-2161
CVE-2022-2157
CVE-2022-2165
CVE-2022-2160
CVE-2022-33638
CVE-2022-2162
CVE-2022-2163
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Edge
CVE-IDS
CVE-2022-21605.0Warning
CVE-2022-21645.0Warning
CVE-2022-21655.0Warning
CVE-2022-21585.0Warning
CVE-2022-21635.0Warning
CVE-2022-21575.0Warning
CVE-2022-21565.0Warning
CVE-2022-21625.0Warning
CVE-2022-21615.0Warning
CVE-2022-301925.1High
CVE-2022-336385.1High