Microsoft Edge Security Update – 17 September 2023

Microsoft Edge has released an updated Microsoft Edge Stable version (117.0.2045.31), and version 109 (109.0.1518.140) to fix a zero-day vulnerability.

The addressed vulnerability could allow the remote attacker to exploit it through a malicious WebP image, when the victim opens the compromised image it could trigger a heap buffer overflow within the content process, potentially leading to arbitrary code execution or system compromise.

Heap Buffer Overflow Vulnerability in WebP (CVE-2023-4863):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities

CVE-2023-4863

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References