QID 375575

Date Published: 2021-05-18

QID 375575: Microsoft Edge Based On Chromium Prior to 90.0.818.62 Multiple Vulnerabilities

Microsoft Edge is a cross-platform web browser developed by Microsoft.

Microsoft Edge based on Chromium is affected by the following vulnerabilities:
CVE-2021-30506: Incorrect security UI in Web App Installs.
CVE-2021-30507: Inappropriate implementation in Offline.
CVE-2021-30508: Heap buffer overflow in Media Feeds.
CVE-2021-30509: Out of bounds write in Tab Strip.
CVE-2021-30510: Race in Aura.
CVE-2021-30511: Out of bounds read in Tab Groups.
CVE-2021-30512: Use after free in Notifications.
CVE-2021-30513: Type Confusion in V8.
CVE-2021-30514: Use after free in Autofill.
CVE-2021-30515: Use after free in File API.
CVE-2021-30516: Heap buffer overflow in History.
CVE-2021-30517: Type Confusion in V8.
CVE-2021-30518: Heap buffer overflow in Reader Mode.
CVE-2021-30519: Use after free in Payments.
CVE-2021-30520: Use after free in Tab Strip.

QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.

Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary code on target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to version
    For further details refer to 90.0.818.62 or later
    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-30520 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30520