QID 375822

Date Published: 2021-09-06

QID 375822: Microsoft Edge Based On Chromium Prior to 93.0.961.38 Multiple Vulnerabilities

Microsoft Edge is a cross-platform web browser developed by Microsoft.

CVE-2021-38642 Microsoft Edge (Chromium-based)
CVE-2021-38641 Microsoft Edge (Chromium-based)
CVE-2021-26436 Microsoft Edge (Chromium-based)
CVE-2021-36930 Microsoft Edge (Chromium-based)
CVE-2021-30624 Microsoft Edge (Chromium-based)
CVE-2021-30623 Microsoft Edge (Chromium-based)
CVE-2021-30622 Microsoft Edge (Chromium-based)
CVE-2021-30621 Microsoft Edge (Chromium-based)
CVE-2021-30620 Microsoft Edge (Chromium-based)
CVE-2021-30619 Microsoft Edge (Chromium-based)
CVE-2021-30618 Microsoft Edge (Chromium-based)
CVE-2021-30617 Microsoft Edge (Chromium-based)
CVE-2021-30616 Microsoft Edge (Chromium-based)
CVE-2021-30615 Microsoft Edge (Chromium-based)
CVE-2021-30614 Microsoft Edge (Chromium-based)
CVE-2021-30613 Microsoft Edge (Chromium-based)
CVE-2021-30612 Microsoft Edge (Chromium-based)
CVE-2021-30611 Microsoft Edge (Chromium-based)
CVE-2021-30610 Microsoft Edge (Chromium-based)
CVE-2021-30609 Microsoft Edge (Chromium-based)
CVE-2021-30608 Microsoft Edge (Chromium-based)
CVE-2021-30607 Microsoft Edge (Chromium-based)
CVE-2021-30606 Microsoft Edge (Chromium-based)

Affected Versions:
Microsoft Edge Based On Chromium versions before 93.0.961.38

QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.

Operating System: MacOS
The QID checks for the version of Microsoft Edge Based On Chromium app.

Successful exploitation allows an attacker to compromise the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to version 93.0.961.38 or later
    Software Advisories
    Advisory ID Software Component Link
    Version 93.0.961.38 URL Logo docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-2-2021