Lucene search

K
kasperskyKaspersky LabKLA49158
HistoryMay 05, 2023 - 12:00 a.m.

KLA49158 Multiple vulnerabilities in Microsoft Browser

2023-05-0500:00:00
Kaspersky Lab
threats.kaspersky.com
13
microsoft browser
vulnerabilities
security bypass
privilege escalation
arbitrary code execution
denial of service
spoofing
microsoft edge
chromium-based
settings
updates
cve-2023-29354
cve-2023-29350
cve-2023-2468
cve-2023-2462
cve-2023-2460
cve-2023-2464
cve-2023-2459
cve-2023-2467
cve-2023-2466
cve-2023-2465
cve-2023-2463
ace

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.005

Percentile

75.9%

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to bypass security restrictions, gain privileges, execute arbitrary code, cause denial of service, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A security feature bypass vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to bypass security restrictions.
  2. An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
  3. Implementation vulnerability in PictureInPicture can be exploited to cause denial of service.
  4. Implementation vulnerability in Prompts can be exploited to cause denial of service.
  5. Validation of untrusted input vulnerability in Exte can be exploited to cause denial of service.
  6. Implementation vulnerability in CORS can be exploited to cause denial of service.
  7. Implementation vulnerability in Full Screen Mode can be exploited to cause denial of service.

Original advisories

CVE-2023-29354

CVE-2023-29350

CVE-2023-2468

CVE-2023-2462

CVE-2023-2460

CVE-2023-2464

CVE-2023-2459

CVE-2023-2467

CVE-2023-2466

CVE-2023-2465

CVE-2023-2463

Related products

Microsoft-Edge

CVE list

CVE-2023-2460 high

CVE-2023-2462 warning

CVE-2023-2467 warning

CVE-2023-2464 warning

CVE-2023-2465 warning

CVE-2023-2466 warning

CVE-2023-2463 warning

CVE-2023-2459 high

CVE-2023-2468 warning

CVE-2023-29354 warning

CVE-2023-29350 critical

KB list

Solution

Install necessary updates from the Settings and more menu, that are listed in your About Microsoft Edge page (Microsoft Edge About page usually can be accessed from the Help and feedback option)

Microsoft Edge update settings

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Microsoft Edge (Chromium-based)

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.005

Percentile

75.9%