Microsoft Edge Security Update – 06 June 2023

Microsoft has released an updated Edge version to fix Microsoft Edge-specific vulnerabilities, as well as chromium-based vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to perform various attacks such as bypassing security restrictions, gaining elevated privileges, or gaining access to the vulnerable system.

Sample of the addressed vulnerabilities:

1. Microsoft Edge Privilege Escalation Vulnerability (CVE-2023-33143):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privileges

2. Microsoft Edge Security Feature Bypass Vulnerability (CVE-2023-29345):

  • CVSS: 6.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Bypass Security

It should be highlighted that Microsoft is aware of recent exploits existing in the wild, and working to release security patches. Also, it is worth noting that Microsoft Edge’s enhanced security mode feature helps to mitigate the flaw.

Vulnerabilities

• CVE-2023-33143

• CVE-2023-29345

• CVE-2023-2929

• CVE-2023-2930

• CVE-2023-2931

• CVE-2023-2932

• CVE-2023-2933

• CVE-2023-2934

• CVE-2023-2935

• CVE-2023-2936

• CVE-2023-2937

• CVE-2023-2938

• CVE-2023-2939

• CVE-2023-2940

• CVE-2023-2941

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References