QID 375830

Date Published: 2021-08-23

QID 375830: Microsoft Edge Based On Chromium Prior to 92.0.902.78 Multiple Vulnerabilities

Microsoft Edge is a cross-platform web browser developed by Microsoft.

CVE-2021-30598 Microsoft Edge (Chromium-based)
CVE-2021-30599 Microsoft Edge (Chromium-based)
CVE-2021-30601 Microsoft Edge (Chromium-based)
CVE-2021-30602 Microsoft Edge (Chromium-based)
CVE-2021-30693 Microsoft Edge (Chromium-based)
CVE-2021-30604 Microsoft Edge (Chromium-based)
Affected Versions:
Microsoft Edge Based On Chromium versions before 92.0.902.67

QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.

Operating System: MacOS
The QID checks for the version of Microsoft Edge Based On Chromium app.

Successful exploitation allows an attacker to compromise the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to version 92.0.902.78 or later
    Software Advisories
    Advisory ID Software Component Link
    Version 92.0.902.78 URL Logo docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#august-19-2021