Original Release Date: 9/28/2020
Multiple vulnerabilities have been discovered in Microsoft Edge, the most severe of which could allow for arbitrary code execution. Microsoft Edge is a web browser used to access the Internet. Successful exploitation of the most severe of these vulnerabilities could allow an attacker to execute arbitrary code in the context of the browser. Depending on the privileges associated with the application, an attacker could view, change, or delete data. If this application has been configured to have fewer user rights on the system, exploitation of the most severe of these vulnerabilities could have less impact than if it was configured with administrative rights.
There are currently no reports of these vulnerabilities being exploited in the wild.
Multiple vulnerabilities have been discovered in Microsoft Edge, the most severe of which could allow for arbitrary code execution. These vulnerabilities can be exploited if a user visits, or is redirected to, a specially crafted web page. Details of the vulnerabilities are as follows:
We recommend the following actions be taken:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200002
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15960
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15961
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15962
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15963
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15965
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15966
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15964
We encourage recipients who discover signs of malicious cyber activity to contact us via the cyber incident report form by clicking here.