QID 375627

Date Published: 2021-06-15

QID 375627: Microsoft Edge Based On Chromium Prior to 91.0.864.48 Type Confusion Vulnerability

Microsoft Edge is a cross-platform web browser developed by Microsoft.

Affected Versions:
Microsoft Edge Based On Chromium versions before 91.0.864.48

QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.

Operating System: MacOS
The QID checks for the version of Microsoft Edge Based On Chromium app.

Successful exploitation of this vulnerability may lead to remote code execution.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Customers are advised to upgrade to version 91.0.864.48 or later
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-30551 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-30551