CERT-In Vulnerability Note
CIVN-2023-0384
Remote Code Execution Vulnerability in Microsoft Edge (Chromium-based)
Original Issue Date:December 22, 2023
Severity Rating: HIGH
Software Affected
- Microsoft Edge version prior to 120.0.2210.91
Overview
A vulnerability has been reported in Microsoft Edge (Chromium-based), which could allow an attacker to execute arbitrary code on the targeted system.
Description
This vulnerability exists in Microsoft Edge (Chromium-based) due to Heap buffer overflow in WebRTC. An attacker could exploit this vulnerability by sending a specially crafted request.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the targeted system.
Note: It is reported that the vulnerability (CVE-2023-7024) is being exploited in the wild. Users are advised to apply the patch urgently.
Solution
Apply appropriate updates as mentioned:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-7024
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-7024
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-7024
CVE Name
CVE-2023-7024
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|