KLA12572
Multiple vulnerabilities in Microsoft Browser

Updated: 06/24/2022
Detect date
?
06/23/2022
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, gain privileges.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in Base can be exploited to cause denial of service or execute arbitrary code.
  2. Inappropriate implementation vulnerability in Extensions API can be exploited to cause denial of service.
  3. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  4. Type confusion vulnerability in V8 can be exploited to cause denial of service.
  5. Use after free vulnerability in WebApp Provider can be exploited to cause denial of service or execute arbitrary code.
  6. Use after free vulnerability in Interest groups can be exploited to cause denial of service or execute arbitrary code.
  7. Insufficient data validation in URL formatting can be exploited to cause denial of service.
  8. Insufficient policy enforcement in DevTools can be exploited to cause denial of service.
  9. Insufficient policy enforcement in File System API can be exploited to cause denial of service
  10. Use after free vulnerability in Cast UI and Toolbar can be exploited to cause denial of service or execute arbitrary code.
Affected products

Microsoft Edge (Chromium-based)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-2156
CVE-2022-2164
CVE-2022-30192
CVE-2022-2158
CVE-2022-2161
CVE-2022-2157
CVE-2022-2165
CVE-2022-2160
CVE-2022-33638
CVE-2022-2162
CVE-2022-2163

Impacts
?
ACE 
[?]

DoS 
[?]

PE 
[?]
Related products
Microsoft Edge
Find out the statistics of the vulnerabilities spreading in your region