Critical Remote Code Execution Flaw in Microsoft Edge Grants Full System Control to Attackers

A newly identified vulnerability in Microsoft Edge could potentially allow attackers to gain control of compromised systems by executing code from a remote location. This flaw, designated CVE-2024-38210, has been classified by Microsoft with a severity level of “Important.”

The issue impacts Microsoft Edge (Stable) versions prior to 128.0.2739.42. To exploit this vulnerability, an attacker would need to either:

  1. Gain access to the target system and execute a specially designed application, or
  2. Persuade a local user to open a malicious file, often through deceptive means like phishing emails or instant messages.

Successful exploitation of this vulnerability could enable an attacker to run arbitrary code on the targeted system, potentially leading to full control. The attack necessitates user interaction and multiple steps to exploit the flaw.

Microsoft has resolved this issue in the most recent update. Users are strongly encouraged to upgrade to Microsoft Edge (Stable) version 128.0.2739.42 or newer to address this risk.

This vulnerability is among several security issues that Microsoft has recently patched. To safeguard against similar threats, users should:

  • Regularly update their software
  • Exercise caution when handling files or links from unfamiliar sources
  • Employ strong security practices, including email filtering and user training

While there is no specific information on current exploits for CVE-2024-38210, public disclosure could accelerate the development of such exploits.

Organizations are advised to stay informed through Microsoft’s security updates and CISA’s KEV Catalog for the latest on exploited vulnerabilities.

To verify your Microsoft Edge version, open the browser, click the three-dot menu (…) in the upper-right corner, then go to Help and Feedback > About Microsoft Edge. The version number will be displayed.

If your version is older than 128.0.2739.42, update Edge to the latest version. Edge typically updates automatically, but you can manually check for updates on the About Microsoft Edge page.

Additionally, Google has recently patched a critical zero-day vulnerability in its Chrome browser. Users of Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, should also ensure they apply the latest security updates.

More Articles & Posts