Microsoft Edge Security Update – 19 January 2025

Microsoft has released an updated version of Microsoft Edge “132.0.2957.115” and a version of Microsoft Edge Update Setup “1.3.195.43” to address multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to perform spoofing attacks, obtain sensitive information, gain elevated privileges, or gain access to the affected systems.

Sample of the addressed vulnerabilities:

1. Microsoft Edge Buffer Overflow Vulnerability (CVE-2025-0434):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Microsoft Edge Elevation of Privilege Vulnerability (CVE-2025-21185):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privilege
Vulnerabilities
  • CVE-2025-0434
  • CVE-2025-0435
  • CVE-2025-0436
  • CVE-2025-0437
  • CVE-2025-0438
  • CVE-2025-0439
  • CVE-2025-0440
  • CVE-2025-0441
  • CVE-2025-0442
  • CVE-2025-0443
  • CVE-2025-0446
  • CVE-2025-0447
  • CVE-2025-0448
  • CVE-2025-21399
  • CVE-2025-21185
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References