CERT-In Vulnerability Note
CIVN-2023-0032
Multiple Vulnerabilities in Microsoft Edge (Chromium-based)
Original Issue Date:January 25, 2023
Severity Rating: HIGH
Software Affected
- Microsoft Edge (Chromium-based) versions prior to 109.0.1518.61
Overview
Multiple vulnerabilities have been reported in Microsoft Edge (Chromium-based) which could be exploited by a remote attacker to gain elevated privilege and bypass security restrictions on the targeted system.
Description
These Vulnerabilities exist in Microsoft Edge (Chromium Based). A remote attacker could exploit these vulnerabilities by sending a specially-crafted request on the targeted system.
Successful exploitation of these vulnerabilities could allow a remote attacker to gain elevated privilege and bypass security restrictions on the targeted systems.
Solution
Upgrade to Microsoft Edge version to 109.0.1518.61
https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#january-19-2023
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21795
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21719
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21795
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21719
CVE Name
CVE-2023-21719
CVE-2023-21795
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|