Severity

Medium

Analysis Summary

CVE-2023-36027 CVSS:6.3

Microsoft Edge (Chromium-based) could allow a remote attacker to gain elevated privileges on the system. By persuading a victim to open a specially crafted content, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2023-36014 CVSS:7.3

Microsoft Edge (Chromium-based) could allow a remote attacker to execute arbitrary code on the system. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-36024 CVSS:7.1

Microsoft Edge (Chromium-based) could allow a remote attacker to gain elevated privileges on the system. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

Impact

  • Code Execution
  • Privileges Escalation

Indicators Of Compromise

CVE

  • CVE-2023-36027
  • CVE-2023-36014
  • CVE-2023-36024

Affected Vendors

Microsoft

Affected Products

  • Microsoft Edge (Chromium-based)
  • Microsoft Edge (Chromium-based) 118.0
  • Microsoft Edge (Chromium-based) 119.0

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2023-36027

CVE-2023-36014

CVE-2023-36024