Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
The vulnerability is related to a memory error classified as use-after-free (CWE-416), involving accessing a memory area after it has been freed. The attack vector is network-based and does not require authentication — it is sufficient for a user to visit or interact with a crafted website or content. The flaw enables crossing process isolation boundaries (scope: Changed), meaning it can affect resources beyond the direct browser context.
Successful exploitation of this vulnerability may allow an attacker to escalate privileges and gain full control over the confidentiality, integrity, and availability of the system, potentially enabling code execution in a privileged context or breaking out of the browser sandbox.
Patches available from the vendor should be applied immediately according to references published by the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35618. It is recommended to update Microsoft Edge browser to the latest available version.
Microsoft Edge in versions based on the Chromium engine — specific versions indicated in the vendor's references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMicrosoft Edge
APPMicrosoft< 120.0.2210.61
Related vulnerabilities
Integer overflow w Skia w Google Chrome — sandbox escape
Heap buffer overflow w GPU w Google Chrome — sandbox escape
Type Confusion w Microsoft Edge (Chromium) umożliwia zdalne wykonanie kodu
Eskalacja uprawnień w Microsoft Edge (Chromium) — CVE-2024-21326
Microsoft Edge (Chromium) — Elevation of Privilege przez use-after-free