Microsoft Edge (Chromium) < 85.0.564.44 RCE

medium Nessus Plugin ID 140792

Synopsis

The remote host has an web browser installed that is affected by a remote code execution vulnerability.

Description

The version of Microsoft Edge (Chromium) installed on the remote Windows host is prior to 85.0.564.44. It is, therefore, affected by a remote code execution vulnerability. The vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. An unauthenticated, remote attacker can exploit this, by convincing a user to visit a specially crafted website designed to exploit this vulnerability, to execute arbitrary code with the privileges of the current user.

In order for the host to be vulnerable, it also must have Internet Explorer enabled, as only users that use Internet Explorer to browse the internet are affected.

Note that Nessus has not attempted to exploit this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Microsoft Edge (Chromium) 85.0.564.44 or later.

See Also

http://www.nessus.org/u?7361a589

http://www.nessus.org/u?2ec7f076

Plugin Details

Severity: Medium

ID: 140792

File Name: microsoft_edge_chromium_85_0_564_44.nasl

Version: 1.5

Type: local

Agent: windows

Family: Windows

Published: 9/25/2020

Updated: 2/20/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.3

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-16884

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:edge, cpe:/a:microsoft:ie

Required KB Items: SMB/Registry/Enumerated, SMB/ARCH, installed_sw/Microsoft Edge (Chromium)

Exploit Ease: No known exploits are available

Patch Publication Date: 8/31/2020

Vulnerability Publication Date: 9/8/2020

Reference Information

CVE: CVE-2020-16884