CERT-In Vulnerability Note
CIVN-2024-0082
Remote Code Execution vulnerabilities in Microsoft Edge
Original Issue Date:March 05, 2024
Severity Rating: HIGH
Software Affected
- Microsoft Edge (Stable) versions prior to 122.0.2365.63
Overview
Multiple vulnerabilities have been reported in Microsoft Edge (Stable) which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
These vulnerabilities exist in in Microsoft Edge due to Type Confusion in V8. A remote attacker could exploit these vulnerabilities by sending a specially crafted request on the targeted system.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-1938
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-1939
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-1938
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-1939
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-1938
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-1939
CVE Name
CVE-2024-1938
CVE-2024-1939
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|