CERT-In Vulnerability Note
CIVN-2023-0347
Multiple Vulnerabilities in Microsoft Edge (Chromium Based)
Original Issue Date:November 23, 2023
Severity Rating: MEDIUM
Software Affected
- Microsoft Edge (Stable) prior to 119.0.2151.72
- Microsoft Edge (Extended Stable) prior to 118.0.2088.109
Overview
Multiple vulnerabilities have been reported in Microsoft Edge which could be exploited by a remote attacker to execute arbitrary code and conduct spoofing attacks on the targeted system.
Description
Multiple vulnerabilities exist in Microsoft Edge due to unspecified flaw. A remote attacker could exploit this vulnerability by persuading a victim to visit a specially crafted website.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code and conduct spoofing attacks on the targeted system.
Solution
Apply appropriate updates as mentioned
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#november-16-2023
Vendor Information
Microsoft
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#november-16-2023
References
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#november-16-2023
CVE Name
CVE-2023-36008
CVE-2023-36026
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|