Searching
..

Click anywhere to stop

KLA61868
Multiple vulnerabilities in Microsoft Browser

Обновлено: 25/01/2024
Дата обнаружения
02/11/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in Side Panel can be exploited to cause denial of service or execute arbitrary code.
  2. Use after free vulnerability in Printing can be exploited to cause denial of service or execute arbitrary code.
  3. Integer overflow vulnerability in USB can be exploited to cause execute arbitrary code and denial of service.
  4. Implementation vulnerability in Payments can be exploited to cause denial of service.
  5. Security UI vulnerability in Picture In Picture can be exploited to spoof user interface.
  6. A remote code execution vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to execute arbitrary code.
  7. Security UI vulnerability in Downloads can be exploited to spoof user interface.
  8. Implementation vulnerability in Downloads can be exploited to cause denial of service.
  9. Implementation vulnerability in WebApp Provider can be exploited to cause denial of service.
  10. Use after free vulnerability in Reading Mode can be exploited to cause denial of service or execute arbitrary code.
  11. A spoofing vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to spoof user interface.
  12. Use after free vulnerability in Profiles can be exploited to cause denial of service or execute arbitrary code.
  13. Data validation vulnerability in USB can be exploited to cause denial of service.
Пораженные продукты

Microsoft Edge (Chromium-based)
Microsoft Edge for Android
Microsoft Edge (Chromium-based) Extended Stable

Решение

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)
Microsoft Edge update settings

Первичный источник обнаружения
CVE-2023-5856
CVE-2023-5852
CVE-2023-5849
CVE-2023-5480
CVE-2023-5859
CVE-2023-36022
CVE-2023-5853
CVE-2023-36034
CVE-2023-5851
CVE-2023-5858
CVE-2023-5855
CVE-2023-5850
CVE-2023-36029
CVE-2023-5854
CVE-2023-5482
CVE-2023-5857
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]

SUI 
[?]
Связанные продукты
Microsoft Edge
CVE-IDS
CVE-2023-54806.1High
CVE-2023-58514.3Warning
CVE-2023-54828.8Critical
CVE-2023-58568.8Critical
CVE-2023-58528.8Critical
CVE-2023-58594.3Warning
CVE-2023-58558.8Critical
CVE-2023-58504.3Warning
CVE-2023-58498.8Critical
CVE-2023-58534.3Warning
CVE-2023-58548.8Critical
CVE-2023-58578.8Critical
CVE-2023-58584.3Warning
CVE-2023-360226.6High
CVE-2023-360347.3High
CVE-2023-360294.3Warning