
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
===========================================================================
AUSCERT Security Bulletin
ASB-2021.0049.2
Microsoft Security Update Release for Microsoft Edge (Chromium-based)
17 May 2021
===========================================================================
AusCERT Security Bulletin Summary
———————————
Product: Microsoft Edge (Chromium-based)
Operating System: Windows
Impact/Access: Execute Arbitrary Code/Commands — Remote with User Interaction
Denial of Service — Remote with User Interaction
Access Confidential Data — Remote with User Interaction
Unauthorised Access — Remote with User Interaction
Reduced Security — Remote with User Interaction
Resolution: Patch/Upgrade
CVE Names: CVE-2021-27844 CVE-2021-21190 CVE-2021-21189
CVE-2021-21188 CVE-2021-21187 CVE-2021-21186
CVE-2021-21185 CVE-2021-21184 CVE-2021-21183
CVE-2021-21182 CVE-2021-21180 CVE-2021-21179
CVE-2021-21178 CVE-2021-21177 CVE-2021-21176
CVE-2021-21175 CVE-2021-21174 CVE-2021-21173
CVE-2021-21172 CVE-2021-21171 CVE-2021-21170
CVE-2021-21169 CVE-2021-21168 CVE-2021-21167
CVE-2021-21166 CVE-2021-21165 CVE-2021-21164
CVE-2021-21163 CVE-2021-21162 CVE-2021-21161
CVE-2021-21160 CVE-2021-21159 CVE-2020-21181
Reference: ESB-2021.0803
Revision History: May 17 2021: Fixed typo in product name
March 9 2021: Initial Release
OVERVIEW
The following Chrome CVEs have been released on March 4, 2021.
These CVE were assigned by Chrome. Microsoft Edge (Chromium-based)
ingests Chromium, which addresses these vulnerabilities.
Please see Google Chrome Releases for more information. [1]
Edge version: 89.0.774.45
Chromium version: 89.0.4389.72 [2]
IMPACT
The following vulnerabilities have been addressed:
*CVE-2021-21159
*CVE-2021-21160
*CVE-2021-21161
*CVE-2021-21162
*CVE-2021-21163
*CVE-2021-21164
*CVE-2021-21165
*CVE-2021-21166
*CVE-2021-21167
*CVE-2021-21168
*CVE-2021-21169
*CVE-2021-21170
*CVE-2021-21171
*CVE-2021-21172
*CVE-2021-21173
*CVE-2021-21174
*CVE-2021-21175
*CVE-2021-21176
*CVE-2021-21177
*CVE-2021-21178
*CVE-2021-21179
*CVE-2021-21180
*CVE-2021-27844
*CVE-2020-21181
*CVE-2021-21182
*CVE-2021-21183
*CVE-2021-21184
*CVE-2021-21185
*CVE-2021-21186
*CVE-2021-21187
*CVE-2021-21188
*CVE-2021-21189
*CVE-2021-21190
See Security Update Guide Supports CVEs Assigned by Industry Partners [3]
for more information about third-party CVEs in the Security Update Guide.
MITIGATION
It is advised to update Edge to the latest release.
REFERENCES
[1] Google Chrome Releases
https://chromereleases.googleblog.com/2021
[2] Security Update Guide
https://msrc.microsoft.com/update-guide/en-us
[3] Security Update Guide Supports CVEs Assigned by Industry Partners
https://msrc-blog.microsoft.com/2021/01/13/security-update-guide-supports-cves-assigned-by-industry-partners/
AusCERT has made every effort to ensure that the information contained
in this document is accurate. However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation’s site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
—–BEGIN PGP SIGNATURE—–
Comment: http://www.auscert.org.au/render.html?it=1967
iQIVAwUBYKIKCeNLKJtyKPYoAQgHrhAAlKI1EQC4j7Gjl725ZLVCc7y0alO4Rl3D
yohtvG35LGu3foXEfR86OKLU+Wm3mSmM8ii8oWRCLhsvRo9+JMuW/bx+Krxe1HT2
OxP0huBOmw0dzxGFzKs/HB9vJxXFxXVCK8k2wmW8g3wcgR4rjltXVNulE5DJxpTB
if6hRZZyWSi7kWxoJKHb+s0hermGpJecxptzb+AS8W1mugsoLIHfRmle85Des+7G
6pwnM8ANmaX70qhCCPR6FeRaTJ6H4O4kp2+lf/icVQ9GxiUvPDHmQrCNvike26tK
gG+RxLsCEq+97XGD4VkivjXImSjLrvSxC45sLoJNtOpV1N7a8PnrUCkvvMU1ZHc8
VLjTPAb6nZ4iK24elhiPU1s9j1+SQW+3U1WcHj55PfZMS593LyoA3jZWtbPlzcB0
aX2YjNMAOwm0PXKJ41p5D5dsODg/3/rXbKymGAFl9EjCrcbVpmaC1pFl2f9glJx/
RXjcXzfkX6ZsMNc6r2SQ4khUDS8aw6R3fRPKUAnRc54wWEIAvltfu/l3R5vUWnks
zyt5js5JGkNuFwUMzJKJyQBMshMx1VSg6TLXZKX20vTYLLVI84iRYgWAD/8ZF+xq
2FyNjU/ehYmPmfCvOJjP3MScIZOkf9gia259QBz1Dh6bYaslG6/AiAvM69C7SuqN
RCst1jTQxnQ=
=mPPb
—–END PGP SIGNATURE—–
The post ASB-2021.0049.2 – UPDATE [Win] Microsoft Edge (Chromium-based): Multiple vulnerabilities appeared first on Malware Devil.
https://malwaredevil.com/2021/05/17/asb-2021-0049-2-update-win-microsoft-edge-chromium-based-multiple-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=asb-2021-0049-2-update-win-microsoft-edge-chromium-based-multiple-vulnerabilities
No comments:
Post a Comment