CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-35618

CVSS 9.6v3.1pub. 2023-12-07upd. 2025-01-01

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

🤖 AI Analysis
How it works

The vulnerability is related to a memory error classified as use-after-free (CWE-416), involving accessing a memory area after it has been freed. The attack vector is network-based and does not require authentication — it is sufficient for a user to visit or interact with a crafted website or content. The flaw enables crossing process isolation boundaries (scope: Changed), meaning it can affect resources beyond the direct browser context.

Impact

Successful exploitation of this vulnerability may allow an attacker to escalate privileges and gain full control over the confidentiality, integrity, and availability of the system, potentially enabling code execution in a privileged context or breaking out of the browser sandbox.

Mitigation & patch

Patches available from the vendor should be applied immediately according to references published by the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35618. It is recommended to update Microsoft Edge browser to the latest available version.

Who is affected

Microsoft Edge in versions based on the Chromium engine — specific versions indicated in the vendor's references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Microsoft Edge

    APP
    Microsoft
    < 120.0.2210.61
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2023-6345CRITICAL9.6⚠ KEVPL ✓same product

Integer overflow w Skia w Google Chrome — sandbox escape

CVE-2022-4135CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w GPU w Google Chrome — sandbox escape

CVE-2026-58289CRITICAL9.0PL ✓same product

Type Confusion w Microsoft Edge (Chromium) umożliwia zdalne wykonanie kodu

CVE-2024-21326CRITICAL9.6PL ✓same product

Eskalacja uprawnień w Microsoft Edge (Chromium) — CVE-2024-21326

CVE-2023-36735CRITICAL9.6PL ✓same product

Microsoft Edge (Chromium) — Elevation of Privilege przez use-after-free