SB2023072202 - Multiple vulnerabilities in Microsoft Edge
Published: July 22, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 13 secuirty vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2023-3727)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebRTC component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
2) Use-after-free (CVE-ID: CVE-2023-3728)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the WebRTC component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
3) Use-after-free (CVE-ID: CVE-2023-3730)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the Tab Groups component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
4) Buffer overflow (CVE-ID: CVE-2023-3732)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in Mojo in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a stack-based buffer overflow and execute arbitrary code on the system.
5) Improperly implemented security check for standard (CVE-ID: CVE-2023-3733)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in WebApp Installs in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
6) Improperly implemented security check for standard (CVE-ID: CVE-2023-3734)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Picture In Picture in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
7) Improperly implemented security check for standard (CVE-ID: CVE-2023-3735)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Web API Permission Prompts in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
8) Improperly implemented security check for standard (CVE-ID: CVE-2023-3736)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Custom Tabs in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
9) Improperly implemented security check for standard (CVE-ID: CVE-2023-3737)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Notifications in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
10) Improperly implemented security check for standard (CVE-ID: CVE-2023-3738)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Autofill in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
11) Input validation error (CVE-ID: CVE-2023-3740)
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a improper input validation in Themes in Google Chrome. A remote attacker can trick the victim to perform certain actions in browser and crash it.
12) Spoofing attack (CVE-ID: CVE-2023-35392)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can spoof the page content of another browser instance.
13) Input validation error (CVE-ID: CVE-2023-38187)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to open a specially crafted website and gain access to sensitive information or interact with browser API.
Remediation
Install update from vendor's website.
References
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3727
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3728
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3730
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3732
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3733
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3734
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3735
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3736
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3737
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3738
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-3740
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35392
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38187