Microsoft Edge Security Update – 24 July 2023

Microsoft has released an updated Edge version (115.0.1901.183) and extended stable version (114.0.1823.90) to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the attacker to gain privileges or trigger spoofing attack by persuading the victim to open specially crafted file or request.

Sample of the addressed vulnerabilities:

Microsoft Edge (Chromium-based) Privilege Escalation (CVE-2023-38187):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2023-38187
  • CVE-2023-38173
  • CVE-2023-35392
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References