Critical Flaw in Microsoft Edge Allows Unauthorized Code Execution

Microsoft has issued a vital security update for its Edge browser to fix multiple vulnerabilities, including a critical validation flaw that could enable attackers to execute arbitrary code on compromised systems.

Released on August 1, 2024, this update addresses three key vulnerabilities in Microsoft Edge versions prior to 127.0.2651.86:

  • CVE-2024-7256: Inadequate data validation in the Dawn component (High severity)
  • CVE-2024-6990: Uninitialized Use in the Dawn component (Critical severity)
  • CVE-2024-7255: Out-of-bounds read in the WebTransport feature (High severity)

The most critical of these, CVE-2024-7256, involves a validation flaw in the Dawn graphics component, allowing attackers to run arbitrary code on the victim’s machine. This vulnerability was identified by a security researcher known as “gelatin dessert” on July 23, 2024.
Microsoft has classified CVE-2024-6990 as “Critical.” This uninitialized use vulnerability in the Dawn component could result in out-of-bounds memory access.

The third vulnerability, CVE-2024-7255, impacts the WebTransport feature, potentially enabling attackers to conduct out-of-bounds memory read operations.

These security flaws affect Microsoft Edge versions on Windows, macOS, and Linux. Users are strongly urged to update their browsers to the latest version (127.0.2651.86 or later) immediately to minimize these risks.

Typically, Microsoft Edge will update automatically. However, users can manually check for updates by going to the browser’s settings.

Additionally, enabling Microsoft Edge’s enhanced security mode may offer some protection against these vulnerabilities. Users are encouraged to activate this feature for added security.

As always, maintaining up-to-date software and exercising caution when browsing suspicious websites or interacting with dubious content online is crucial for security.

More Articles & Posts