CVE-2021-1705
published 2021-01-12CVE-2021-1705: Microsoft Edge (HTML-based) Memory Corruption Vulnerability
PriorityP339high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.92%
77.7th percentile
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_edge | >= 1.0..0 < publication | publication |
| msrc | microsoft_edge_on_windows_10_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1909_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1909_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_server_2016 | — | — |
| msrc | microsoft_edge_on_windows_server_2019 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9q66-j74h-5mq3: Microsoft Edge (HTML-based) Memory Corruption Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-1705 [HIGH] GHSA-9q66-j74h-5mq3: Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
vendor_msrc·2021-01-12·CVSS 4.2
CVE-2021-1705 [MEDIUM] Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft Edge (HTML-based): Microsoft Edge (HTML-based)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4598245
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4598230
Reference: https://support.microsoft.com/help/4598230
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4598229
Reference: https://support.microsoft.com/help/4598229
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4598242
Refere
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices. Talos also released a new set of SNORTⓇ rules that provide coverage for some of thes
2021-01-12
Published