QID 375575
Date Published: 2021-05-18
QID 375575: Microsoft Edge Based On Chromium Prior to 90.0.818.62 Multiple Vulnerabilities
Microsoft Edge is a cross-platform web browser developed by Microsoft.
Microsoft Edge based on Chromium is affected by the following vulnerabilities:
CVE-2021-30506: Incorrect security UI in Web App Installs.
CVE-2021-30507: Inappropriate implementation in Offline.
CVE-2021-30508: Heap buffer overflow in Media Feeds.
CVE-2021-30509: Out of bounds write in Tab Strip.
CVE-2021-30510: Race in Aura.
CVE-2021-30511: Out of bounds read in Tab Groups.
CVE-2021-30512: Use after free in Notifications.
CVE-2021-30513: Type Confusion in V8.
CVE-2021-30514: Use after free in Autofill.
CVE-2021-30515: Use after free in File API.
CVE-2021-30516: Heap buffer overflow in History.
CVE-2021-30517: Type Confusion in V8.
CVE-2021-30518: Heap buffer overflow in Reader Mode.
CVE-2021-30519: Use after free in Payments.
CVE-2021-30520: Use after free in Tab Strip.
QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.
Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary code on target system.
For further details refer to 90.0.818.62 or later
- CVE-2021-30506 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30506 - CVE-2021-30507 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30507 - CVE-2021-30508 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30508 - CVE-2021-30509 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30509 - CVE-2021-30510 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30510 - CVE-2021-30511 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30511 - CVE-2021-30512 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30512 - CVE-2021-30513 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30513 - CVE-2021-30514 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30514 - CVE-2021-30515 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30515 - CVE-2021-30516 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30516 - CVE-2021-30517 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30517 - CVE-2021-30518 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30518 - CVE-2021-30519 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30519 - CVE-2021-30520 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-30520
CVEs related to QID 375575
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-30520 |
|