Published on: 01 November 2021
Microsoft released a security update to address multiple vulnerabilities in Microsoft Edge (Chromium-based). A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerability.
Reports indicate that the vulnerabilities (CVE-2021-38000 and CVE-2021-38003) are being exploited in the wild. You are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Successful exploitation of the vulnerabilities could lead to remote code execution on an affected system.
Users of affected systems should update Microsoft Edge (Chromium-based) to version 95.0.1020.40 or later to address the issue.
The list of security updates can be found at:
https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#october-29-2021