CERT-In Vulnerability Note
CIVN-2023-0223
Multiple vulnerabilities in Microsoft Edge (Chromium-based)
Original Issue Date:July 28, 2023
Severity Rating: MEDIUM
Software Affected
- Microsoft Edge (Chromium-based) versions prior to 115.0.1901.183
Overview
Multiple vulnerabilities have been reported in Microsoft Edge (Chromium) which could be exploited by a remote attacker to trigger elevation of privilege, spoofing, security restriction bypass, remote code execution, denial of service condition and data manipulation on the targeted system.
Description
Multiple vulnerabilities exist in Microsoft Edge (Chromium) due to Use after free in WebRTC; Use after free in Tab Groups; Out of bounds memory access in Mojo; Inappropriate implementation in WebApp Installs, Picture, Web API Permission Prompts, Custom Tabs, Notifications and Autofill; Insufficient validation of untrusted input in Themes. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted Web site.
Successful exploitation of this vulnerability could allow a remote attacker to trigger elevation of privilege, spoofing, security restriction bypass, remote code execution, denial of service and data manipulation on the targeted system.
Solution
Upgrade to Microsoft Edge version 115.0.1901.183:
https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#july-21-2023
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3727
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3728
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3730
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3732
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3733
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3734
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3735
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3736
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3737
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3738
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-3740
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35392
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38173
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38187
CVE Name
CVE-2023-3727
CVE-2023-3728
CVE-2023-3730
CVE-2023-3732
CVE-2023-3733
CVE-2023-3734
CVE-2023-3735
CVE-2023-3736
CVE-2023-3737
CVE-2023-3738
CVE-2023-3740
CVE-2023-35392
CVE-2023-38173
CVE-2023-38187
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|