QID 375884

Date Published: 2021-09-27

QID 375884: Microsoft Edge Based on Chromium Prior to 94.0.992.31 Multiple Vulnerabilities

CVE-2021-37973 Microsoft Edge (Chromium-based)
CVE-2021-37972 Microsoft Edge (Chromium-based)
CVE-2021-37971 Microsoft Edge (Chromium-based)
CVE-2021-37970 Microsoft Edge (Chromium-based)
CVE-2021-37969 Microsoft Edge (Chromium-based)
CVE-2021-37968 Microsoft Edge (Chromium-based)
CVE-2021-37967 Microsoft Edge (Chromium-based)
CVE-2021-37966 Microsoft Edge (Chromium-based)
CVE-2021-37965 Microsoft Edge (Chromium-based)
CVE-2021-37964 Microsoft Edge (Chromium-based)
CVE-2021-37963 Microsoft Edge (Chromium-based)
CVE-2021-37962 Microsoft Edge (Chromium-based)
CVE-2021-37961 Microsoft Edge (Chromium-based)
CVE-2021-37960 Microsoft Edge (Chromium-based)
CVE-2021-37959 Microsoft Edge (Chromium-based)
CVE-2021-37958 Microsoft Edge (Chromium-based)
CVE-2021-37957 Microsoft Edge (Chromium-based)
CVE-2021-37956 Microsoft Edge (Chromium-based)
Affected Versions:
Microsoft Edge Based On Chromium versions before 94.0.992.31

QID Detection Logic: (authenticated)
Operating System: Windows
The install path is checked via registry "HKLM\SOFTWARE\Clients\StartMenuInternet\Microsoft Edge\shell\open\command". The version is checked via file msedge.exe.

Operating System: MacOS
The QID checks for the version of Microsoft Edge Based On Chromium app.

Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to version 94.0.992.31 or later
    Software Advisories
    Advisory ID Software Component Link
    Edge (chromium based) 94.0.992.31 URL Logo docs.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel#version-94099231-september-24