Microsoft Edge Security Update – 07 May 2023

Microsoft has released an updated Edge version (113.0.1774.35) to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to conduct spoofing attacks, bypass security restrictions, or gain Privileges on the affected systems by persuading the victim to visit a specially crafted website.

Sample of the addressed vulnerabilities:

Microsoft Edge (Chromium-based) Privilege Escalation (CVE-2023-29350):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2023-29334
  • CVE-2023-29350
  • CVE-2023-29354
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References