CVE-2022-21931
published 2022-01-11CVE-2022-21931: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
PriorityP423medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
EPSS
1.19%
64.8th percentile
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 97.0.1072.55 | 97.0.1072.55 |
| microsoft | microsoft_edge | >= 1.0.0 < 97.0.1072.55 | 97.0.1072.55 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6cxm-97vj-636g: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-01-12·CVSS 2.5
CVE-2022-21930 [LOW] GHSA-6cxm-97vj-636g: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21929, CVE-2022-21931.
GHSA
GHSA-7842-6rpw-vgr5: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-01-12·CVSS 2.5
CVE-2022-21931 [LOW] GHSA-7842-6rpw-vgr5: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21929, CVE-2022-21930.
GHSA
GHSA-xm92-6hxv-37gp: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-01-12·CVSS 4.2
CVE-2022-21929 [MEDIUM] GHSA-xm92-6hxv-37gp: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21930, CVE-2022-21931.
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2022-01-11·CVSS 4.2
CVE-2022-21931 [MEDIUM] Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
97.0.1072.55
1/6/2022
97.0.4692.71
Microsoft Edge (Chromium-based): Microsoft Edge (Chromium-based)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for Jan. 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-01-11·CVSS 8.3
CVE-2022-21840 [HIGH] Microsoft Patch Tuesday for Jan. 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 102 vulnerabilities across its large collection of hardware and software. This is the largest amount of vulnerabilities Microsoft has disclosed in a monthly security update in eight months, however, none of the issues have been exploited in the wild, according to Microsoft.
2022’s first security update features nine critical vulnerabilities, with all but one of the remaining being considered “important.” CVE-2022-21840 is one of the critical vulnerabilities, an issue in Microsoft Office that could allow an attacker to execute remote code on the targeted machine. CVE-2022-21841, CVE-2022-21837 and CVE-2022-21842 are also remote code execution vulnerabilities in the Office suite of products, though they are only rated as “im
Talos
Microsoft Patch Tuesday for Jan. 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-01-11·CVSS 8.3
[HIGH] Microsoft Patch Tuesday for Jan. 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Jan. 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 102 vulnerabilities across its large collection of hardware and software. This is the largest amount of vulnerabilities Microsoft has disclosed in a monthly security update in eight months, however, none of the issues have been exploited in the wild, according to Microsoft.
2022’s first security update features nine critical vulnerabilities, with all but one of the remaining being considered “important.” CVE-2022-21840 is one of the critical vulnerabilities, an issue in Microsoft Office that could allow an attacker to execute remote code on the targeted machine. CVE-2022-21841 , CVE-2022-21837 and CVE-2022-21842 are also remote code execu
2022-01-11
Published