Microsoft Edge Security Update – 27 August 2023

Microsoft has released an updated Microsoft Edge stable version (116.0.1938.62) to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to elevate the privilege or execute arbitrary code on the affected system.

Sample of the addressed vulnerabilities:

1. Microsoft Edge Code Execution Vulnerability (CVE-2023-4427):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Microsoft Edge Elevation of Privilege Vulnerability (CVE-2023-36741):

  • CVSS: 8.3
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privilege
Vulnerabilities
  • CVE-2023-4427
  • CVE-2023-4428
  • CVE-2023-4429
  • CVE-2023-4430
  • CVE-2023-4431
  • CVE-2023-36741
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References