QID 375456

Date Published: 2021-04-15

QID 375456: Microsoft Edge Based On Chromium Prior to 89.0.774.68 Multiple Vulnerabilities

Microsoft Edge based on Chromium is affected by the following vulnerabilities:
CVE-2021-21194: Use after free in screen capture.
CVE-2021-21195: Use after free in V8.
CVE-2021-21196: Heap buffer overflow in TabStrip.
CVE-2021-21197: Heap buffer overflow in TabStrip.
CVE-2021-21198: Out of bounds read in IPC.
CVE-2021-21199: Use Use after free in Aura

Affected Version:
Microsoft Edge based on Chromium Prior to version 89.0.774.68

QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.

QID Detection Logic: (authenticated)
Operating System: MacOS
The QID checks for vulnerable version of Microsoft Edge from installed application list.

Successful exploitation of this vulnerability affects confidentiality, integrity and availability.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to version
    For further details refer to 89.0.774.68 or later
    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-21194 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-21194