CERT-In Vulnerability Note
CIVN-2021-0350
Multiple Vulnerabilities in Microsoft Edge (Chromium)
Original Issue Date:December 14, 2021
Severity Rating: HIGH
Software Affected
- Microsoft Edge (Chromium) versions prior to 96.0.1054.53
Overview
Multiple vulnerabilities have been reported in Microsoft Edge (Chromium) which could allow a remote attacker to execute arbitrary code and bypass of security restrictions on the targeted system.
Description
Multiple vulnerabilities exist in Microsoft Edge (Chromium) due to Use after free in web apps, UI, file API, developer tools, screen capture, autofill and window manager; Incorrect security UI in autofill; Heap buffer overflow in extensions, BFCache and ANGLE; Type Confusion in loader; Insufficient data validation in loader; Type Confusion in V8; Integer underflow in ANGLE and Insufficient validation of untrusted input in new tab page. A remote attacker could exploit these vulnerabilities by persuading the victim to visit a specially crafted Web site.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code and bypass of security restrictions on the targeted system.
Solution
Upgrade to Microsoft Edge version 96.0.1054.53
https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#december-10-2021
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4052
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4053
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4054
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4055
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4056
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4057
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4058
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4059
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4061
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4062
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4063
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4064
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4065
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4066
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4067
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4068
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4052
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4053
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4054
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4055
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4056
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4057
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4058
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4059
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4061
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4062
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4063
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4064
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4065
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4066
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4067
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4068
CVE Name
CVE-2021-4052
CVE-2021-4053
CVE-2021-4054
CVE-2021-4055
CVE-2021-4056
CVE-2021-4057
CVE-2021-4058
CVE-2021-4059
CVE-2021-4061
CVE-2021-4062
CVE-2021-4063
CVE-2021-4064
CVE-2021-4065
CVE-2021-4066
CVE-2021-4067
CVE-2021-4068
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|