Microsoft Edge Security Update – 16 July 2023

Microsoft has released an updated Edge version (114.0.1823.82) to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the attacker to gain access or trigger a spoofing attack by persuading the victim to open a specially crafted file or request.

Sample of the addressed vulnerabilities:

Microsoft Edge (Chromium-based) Code Execution (CVE-2023-36887):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-36883
  • CVE-2023-36887
  • CVE-2023-36888
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References