Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2021-38669: Microsoft Edge (Chromium-based) Tampering Vulnerability

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 93.0.961.44 9/9/2021 93.04577.63

Microsoft Security Response Center
#Microsoft Edge (Chromium-based)#Security Vulnerability#vulnerability#microsoft
CVE-2021-40444: Microsoft MSHTML Remote Code Execution Vulnerability

By default, Microsoft Office opens documents from the internet in Protected View or Application Guard for Office both of which prevent the current attack. * For information about Protected View, see What is Protected View?. * For information about Application Guard for Office, see Application Guard for Office. Customers of Microsoft Defender for Endpoint can enable attack surface reduction rule "BlockOfficeCreateProcessRule" that blocks Office apps from creating child processes. Creating malicious child processes is a common malware strategy. For more information see Use attack surface reduction rules to prevent malware infection.

CVE-2021-30618: Chromium: CVE-2021-30618 Inappropriate implementation in DevTools

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30617: Chromium: CVE-2021-30617 Policy bypass in Blink

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30616: Chromium: CVE-2021-30616 Use after free in Media

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30615: Chromium: CVE-2021-30615 Cross-origin data leak in Navigation

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30614: Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30613: Chromium: CVE-2021-30613 Use after free in Base internals

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30612: Chromium: CVE-2021-30612 Use after free in WebRTC

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30611: Chromium: CVE-2021-30611 Use after free in WebRTC

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |