Microsoft Edge Security Update – 04 October 2022

Microsoft has released an updated version of Microsoft Edge (Version 106.0.1370.34) to fix a vulnerability in Microsoft Edge. The remote attacker could exploit this vulnerability to take control of the affected system.

The severity of the addressed vulnerability could allow the remote attacker to exploit this vulnerability by persuading a victim to visit a specially crafted Web site to conduct a spoofing attack.

Microsoft Edge (Chromium-based) Spoofing (CVE-2022-41035):

• CVSS: 8.3

• Attack Vector: Network

• Attack Complexity: High

• Privileges Required: None

• User Interaction: Required

• Exploitability: POC

• Consequences: Gain Access

 
Vulnerabilities
  • CVE-2022-41035
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References