KLA51267
Multiple vulnerabilities in Microsoft Browser

Обновлено: 29/09/2023
Дата обнаружения
21/07/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code, spoof user interface, gain privileges.

Below is a complete list of vulnerabilities:

  1. Implementation vulnerability in Web API Permission can be exploited to cause denial of service.
  2. Implementation vulnerability in Custom Tabs can be exploited to cause denial of service.
  3. Implementation vulnerability in Autofill can be exploited to cause denial of service.
  4. Validation of untrusted input vulnerability in Them can be exploited to cause denial of service.
  5. Out of bounds memory access vulnerability in Mojo can be exploited to cause denial of service.
  6. Use after free vulnerability in Tab Groups can be exploited to cause denial of service or execute arbitrary code.
  7. A spoofing vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to spoof user interface.
  8. Implementation vulnerability in Notifications can be exploited to cause denial of service.
  9. Implementation vulnerability in WebApp Installs can be exploited to cause denial of service.
  10. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  11. Use after free vulnerability in WebRTC can be exploited to cause denial of service or execute arbitrary code.
  12. Implementation vulnerability in Picture In Picture can be exploited to cause denial of service.
  13. A spoofing vulnerability in Microsoft Edge for Android can be exploited remotely to spoof user interface.
Пораженные продукты

Microsoft Edge (Chromium-based) Extended Stable
Microsoft Edge for Android
Microsoft Edge (Chromium-based)

Решение

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)
Microsoft Edge update settings

Первичный источник обнаружения
CVE-2023-3735
CVE-2023-3736
CVE-2023-3738
CVE-2023-3740
CVE-2023-3732
CVE-2023-3730
CVE-2023-35392
CVE-2023-3737
CVE-2023-3733
CVE-2023-38187
CVE-2023-3728
CVE-2023-3727
CVE-2023-3734
CVE-2023-38173
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Edge
CVE-IDS
CVE-2023-37335.0Warning
CVE-2023-37405.0Warning
CVE-2023-37385.0Warning
CVE-2023-37365.0Warning
CVE-2023-37345.0Warning
CVE-2023-37285.0Warning
CVE-2023-37325.0Warning
CVE-2023-37305.0Warning
CVE-2023-37275.0Warning
CVE-2023-37375.0Warning
CVE-2023-37355.0Warning
CVE-2023-353925.0Warning
CVE-2023-381875.0Warning
CVE-2023-381735.0Warning