Description:
Microsoft released a security update to address vulnerabilities in Microsoft Edge. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerability.
Affected Systems:
- Microsoft Edge prior to version 133.0.3065.51
Impact:
Successful exploitation of the vulnerability could lead to remote code execution, denial of service, information disclosure or spoofing on an affected system.
Recommendation:
System administrators and users of affected systems should update Microsoft Edge to version 133.0.3065.51 or later to address the issue.
More Information:
- https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#february-6-2025
- https://www.hkcert.org/security-bulletin/microsoft-edge-multiple-vulnerabilities_20250207
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0444 (to CVE-2025-0445)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0451
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21253
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21267
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21279
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21283
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21342
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21404
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21408