Lucene search

K
kasperskyKaspersky LabKLA20163
HistoryJan 12, 2023 - 12:00 a.m.

KLA20163 Multiple vulnerabilities in Microsoft Browser

2023-01-1200:00:00
Kaspersky Lab
threats.kaspersky.com
23
microsoft browser
malicious users
denial of service
gain privileges
execute arbitrary code
file system api
fullscreen api
permission prompts
iframe sandbox
untrusted input
downloads
policy enforcement
cors
elevation of privilege
microsoft edge
use after free
cart
heap buffer overflow
network service
remote code execution
libphonenumber
cve-2023-0130
cve-2023-0132
cve-2023-0131
cve-2023-0139
cve-2023-0133
cve-2023-0140
cve-2023-0131
cve-2023-0141
cve-2023-21796
cve-2023-0136
cve-2023-0134
cve-2023-0129
cve-2023-0135
cve-2023-21775
cve-2023-0138

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.019

Percentile

88.6%

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to cause denial of service, gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Implementation vulnerability in File System API can be exploited to cause denial of service.
  2. Implementation vulnerability in Fullscreen API can be exploited to cause denial of service.
  3. Implementation vulnerability in Permission prompts can be exploited to cause denial of service.
  4. Implementation vulnerability in iframe Sandbox can be exploited to cause denial of service.
  5. Validation of untrusted input vulnerability in Downloads can be exploited to cause denial of service.
  6. Policy enforcement vulnerability in CORS can be exploited to cause denial of service.
  7. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  8. Use after free vulnerability in Cart can be exploited to cause denial of service or execute arbitrary code.
  9. Heap buffer overflow vulnerability in Network Service can be exploited to cause denial of service.
  10. A remote code execution vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to execute arbitrary code.
  11. Heap buffer overflow vulnerability in libphonenumber can be exploited to cause denial of service.

Original advisories

CVE-2023-0140

CVE-2023-0130

CVE-2023-0132

CVE-2023-0131

CVE-2023-0139

CVE-2023-0133

CVE-2023-0141

CVE-2023-21796

CVE-2023-0136

CVE-2023-0134

CVE-2023-0129

CVE-2023-0135

CVE-2023-21775

CVE-2023-0138

Related products

Microsoft-Edge

CVE list

CVE-2023-0129 critical

CVE-2023-0132 high

CVE-2023-0136 critical

CVE-2023-0133 high

CVE-2023-0140 high

CVE-2023-0131 high

CVE-2023-0138 critical

CVE-2023-0135 critical

CVE-2023-0134 critical

CVE-2023-0130 high

CVE-2023-0141 warning

CVE-2023-0139 high

CVE-2023-21796 critical

CVE-2023-21775 critical

KB list

Solution

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)

Microsoft Edge update settings

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Microsoft Edge (Chromium-based)

References

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.019

Percentile

88.6%