Microsoft Edge Security Update – 10 December 2023

Microsoft has released the latest Microsoft Edge Stable Channel (Version 120.0.2210.61) to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security, gain elevated privileges, or disclose sensitive information on the affected system.

Sample of the addressed vulnerabilities:

Microsoft Edge (Chromium-based) Elevation of Privilege (CVE-2023-35618):

  • CVSS: 9.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privilege
Vulnerabilities
  • CVE-2023-38174
  • CVE-2023-35618
  • CVE-2023-36880
  • CVE-2023-6508
  • CVE-2023-6509
  • CVE-2023-6510
  • CVE-2023-6511
  • CVE-2023-6512
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References