Microsoft Edge (Chromium) < 94.0.992.31 Multiple Vulnerabilities

critical Nessus Plugin ID 153666

Synopsis

The remote host has an web browser installed that is affected by multiple vulnerabilities.

Description

The version of Microsoft Edge installed on the remote Windows host is prior to 94.0.992.31. It is, therefore, affected by multiple vulnerabilities as referenced in the September 24, 2021 advisory.

- Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(CVE-2021-37973)

- Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
(CVE-2021-37956)

- Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (CVE-2021-37957)

- Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page. (CVE-2021-37958)

- Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.
(CVE-2021-37959)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Microsoft Edge version 94.0.992.31 or later.

See Also

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37959

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37961

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37962

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37963

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37964

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37965

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37966

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37967

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37968

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37969

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37970

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37971

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37972

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37973

http://www.nessus.org/u?6dbcb9b7

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37956

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37957

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-37958

Plugin Details

Severity: Critical

ID: 153666

File Name: microsoft_edge_chromium_94_0_992_31.nasl

Version: 1.11

Type: local

Agent: windows

Family: Windows

Published: 9/24/2021

Updated: 1/16/2024

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.1

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-37973

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:edge

Required KB Items: installed_sw/Microsoft Edge (Chromium), SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/24/2021

Vulnerability Publication Date: 9/21/2021

CISA Known Exploited Vulnerability Due Dates: 11/17/2021

Reference Information

CVE: CVE-2021-37956, CVE-2021-37957, CVE-2021-37958, CVE-2021-37959, CVE-2021-37961, CVE-2021-37962, CVE-2021-37963, CVE-2021-37964, CVE-2021-37965, CVE-2021-37966, CVE-2021-37967, CVE-2021-37968, CVE-2021-37969, CVE-2021-37970, CVE-2021-37971, CVE-2021-37972, CVE-2021-37973

IAVA: 2021-A-0448-S