Microsoft Edge Privilege Escalation Flaw – Update Now!

Microsoft Edge has published a release note that mentioned a Privilege escalation vulnerability with the CVE ID of CVE-2023-36741 and has a CVSS Score of 8.3 (High). This vulnerability exists in the Microsoft-Edge Chromium-based versions prior to 116.0.1938.62.

An unauthorized remote attacker can exploit this vulnerability which requires the interaction of the user.

The scope of this vulnerability is beyond the vulnerable component of Microsoft Edge. There is no known exploit code available for this vulnerability.

CVE-2023-36741

Microsoft has not provided any additional details about this vulnerability which limits the current knowledge about this vulnerability.

However, Microsoft mentioned in their security advisory that this vulnerability affects the CIA (Confidentiality, Integrity, and Availability) of the affected application and its environment.

In addition, Tenable has released new plugins for Nessus, which users can use to detect this vulnerability. The plugin is as follows,

IDNameProductFamilySeverity
180197Microsoft Edge (Chromium) < 116.0.1938.62 Multiple VulnerabilitiesNessusWindowsHIGH

Source: Tenable

During the previous release notes on August 21, 2023, Microsoft patched two vulnerabilities CVE-2023-38158 & CVE-2023-36787. These vulnerabilities were information disclosure and elevation of privileges patched in the versions Microsoft Edge Stable and Extended Stable Channel (Version 116.0.1938.54).

However, in this current release note, Microsoft has patched only one Elevation of privileges vulnerability, which is the 4th patch update this month. As of the month of July, only two release notes were released.

Users of Chromium-based Microsoft Edge are recommended to upgrade to the latest version in order to fix this vulnerability and prevent exploitation.

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Eswar

Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

25 minutes ago

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems to…

46 minutes ago

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to achieve…

3 hours ago

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication…

3 hours ago

Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution

A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution…

3 hours ago

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March 3,…

4 hours ago