Malware Devil

Friday, June 25, 2021

ASB-2021.0122 – [Win] Microsoft Edge (Chromium-based): Multiple vulnerabilities

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256

===========================================================================
AUSCERT Security Bulletin

ASB-2021.0122
Microsoft Security Update Release for Microsoft Edge (Chromium-based)
25 June 2021

===========================================================================

AusCERT Security Bulletin Summary
———————————

Product: Microsoft Edge (Chromium-based)
Operating System: Windows
Impact/Access: Increased Privileges — Remote with User Interaction
Unauthorised Access — Remote with User Interaction
Resolution: Patch/Upgrade
CVE Names: CVE-2021-34506 CVE-2021-34475

OVERVIEW

The following Chrome CVEs have been released on June 24, 2021.

These CVE were assigned by Chrome. Microsoft Edge (Chromium-based)
ingests Chromium, which addresses these vulnerabilities.
Please see Google Chrome Releases for more information. [1]

Edge version: 91.0.864.59
Chromium version: 91.0.4472.101[2]

IMPACT

The following vulnerability has been addressed:

* CVE-2021-34475 (Elevation of Privilege)
* CVE-2021-34506 (Security Feature Bypass)

See Security Update Guide Supports CVEs Assigned by Industry Partners [3]
for more information about third-party CVEs in the Security Update Guide.

MITIGATION

It is advised to update Edge to the latest release.

REFERENCES

[1] Google Chrome Releases
https://chromereleases.googleblog.com/2021

[2] Security Update Guide
https://msrc.microsoft.com/update-guide/en-us

[3] Security Update Guide Supports CVEs Assigned by Industry Partners
https://msrc-blog.microsoft.com/2021/01/13/security-update-guide-supports-cves-assigned-by-industry-partners/

AusCERT has made every effort to ensure that the information contained
in this document is accurate. However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation’s site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
—–BEGIN PGP SIGNATURE—–
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYNUqBeNLKJtyKPYoAQjsSg/+M+UtvKymP+WFL8gCUJZrLQVnLAxiL0+B
Egge/5GWpD7cKARQL4wnfb+UbPY7C+n0/z9ZADyvgqkJUcaiSO7U1iZ7vVwMJbBI
AHT3PFkPIv1F1edY2yOAJXpjPKrVaj1XsZFNMm2ICEce7Jqa3QcvWfYS8qo+dMH0
OLtodyJDdBeeLfg1LxsYwREyDTdEWqoyiTkYQrtzForPB2wpj9OfzlaGaZy2flbK
W92z12l5vegV18NxbL81Ui+6iILG5ySjp1jAhCyv/B8s72FPBQAHDV0o37N/sYka
/wK3jWa9LHgwiyZTpNBnPuBN2D+lN70qGX/Dh432Apblkl7Gz/OWCIa+PgJ8nmp3
/Y25BNTmh7IqdUD+0LzB4AQ4NVI85Xzs7seavFJ5+30/Km0V++6mtq+llyi0k7d8
3kROSnG3A8XvtELG65lR6qkWld4UAmUmVyELhT9mLt0L9c2iiA7aBNd1ug4zgYxK
kRH+JYibNOYy2H0rRVEC6nSHv/qgCOXXJLvDuqagH4xS5JWq1ISe8OZqeRoHN3NH
KO5AfGQeyIdLnY+cvhXhzLs8vJM/yuqC7NN1auxbxk1ah6enLRyCysc2SSH14m48
QCDlA+7+sAKN8J+/3Z1OvHtMggYJXkXFKHPbySMofvR0RA7RZ19S/mRIUw507q4j
0cpQrt9lMCc=
=OmWH
—–END PGP SIGNATURE—–

Read More

The post ASB-2021.0122 – [Win] Microsoft Edge (Chromium-based): Multiple vulnerabilities appeared first on Malware Devil.



https://malwaredevil.com/2021/06/25/asb-2021-0122-win-microsoft-edge-chromium-based-multiple-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=asb-2021-0122-win-microsoft-edge-chromium-based-multiple-vulnerabilities

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...