Microsoft Edge Privilege Escalation Flaw – Update Now!

Microsoft Edge has published a release note that mentioned a Privilege escalation vulnerability with the CVE ID of CVE-2023-36741 and has a CVSS Score of 8.3 (High). This vulnerability exists in the Microsoft-Edge Chromium-based versions prior to 116.0.1938.62.

An unauthorized remote attacker can exploit this vulnerability which requires the interaction of the user.

The scope of this vulnerability is beyond the vulnerable component of Microsoft Edge. There is no known exploit code available for this vulnerability.

CVE-2023-36741

Microsoft has not provided any additional details about this vulnerability which limits the current knowledge about this vulnerability.

However, Microsoft mentioned in their security advisory that this vulnerability affects the CIA (Confidentiality, Integrity, and Availability) of the affected application and its environment.

In addition, Tenable has released new plugins for Nessus, which users can use to detect this vulnerability. The plugin is as follows,

IDNameProductFamilySeverity
180197Microsoft Edge (Chromium) < 116.0.1938.62 Multiple VulnerabilitiesNessusWindowsHIGH

Source: Tenable

During the previous release notes on August 21, 2023, Microsoft patched two vulnerabilities CVE-2023-38158 & CVE-2023-36787. These vulnerabilities were information disclosure and elevation of privileges patched in the versions Microsoft Edge Stable and Extended Stable Channel (Version 116.0.1938.54).

However, in this current release note, Microsoft has patched only one Elevation of privileges vulnerability, which is the 4th patch update this month. As of the month of July, only two release notes were released.

Users of Chromium-based Microsoft Edge are recommended to upgrade to the latest version in order to fix this vulnerability and prevent exploitation.

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Eswar

Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Cyberhaven Hacked – Chrome Extension With 400,000 users Compromised

Cyberhaven, a prominent cybersecurity company, disclosed that its Chrome extension With 400,000+ users was targeted…

2 hours ago

AT&T and Verizon Hacked – Salt Typhoon Compromised The Network For High Profiles

AT&T and Verizon Communications, two of America's largest telecommunications providers, have confirmed they were targeted…

2 hours ago

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a disguised…

2 days ago

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack…

2 days ago

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in…

2 days ago

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo Alto…

2 days ago