-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2021.0227
   Microsoft Security Update Release for Microsoft Edge (Chromium-based)
                              22 October 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:          Microsoft Edge (Chromium-based)
Operating System: Windows
Impact/Access:    Access Confidential Data -- Remote with User Interaction
                  Denial of Service        -- Remote with User Interaction
                  Reduced Security         -- Remote with User Interaction
Resolution:       Patch/Upgrade
CVE Names:        CVE-2021-42307 CVE-2021-37996 CVE-2021-37995
                  CVE-2021-37994 CVE-2021-37993 CVE-2021-37992
                  CVE-2021-37991 CVE-2021-37990 CVE-2021-37989
                  CVE-2021-37988 CVE-2021-37987 CVE-2021-37986
                  CVE-2021-37985 CVE-2021-37984 CVE-2021-37983
                  CVE-2021-37982 CVE-2021-37981 
Reference:        ESB-2021.3486

OVERVIEW

        The following Chrome CVEs has been released on October 21, 2021.
        
        These CVEs were assigned by Chrome. 
        Microsoft Edge (Chromium-based) ingests Chromium, 
        which addresses these vulnerabilities. 
        Please see Google Chrome Releases for more information. [1]
        
        Edge version: 95.0.1020.30
        Chromium version: 95.0.4638.54 [2]


IMPACT

        The following vulnerabilities has been addressed:
        
        * CVE-2021-42307
        * CVE-2021-37981 
        * CVE-2021-37982 
        * CVE-2021-37983 
        * CVE-2021-37984 
        * CVE-2021-37985 
        * CVE-2021-37986 
        * CVE-2021-37987 
        * CVE-2021-37988 
        * CVE-2021-37989 
        * CVE-2021-37990 
        * CVE-2021-37991 
        * CVE-2021-37992 
        * CVE-2021-37993 
        * CVE-2021-37996 
        * CVE-2021-37994 
        * CVE-2021-37995
        
        See Security Update Guide Supports CVEs Assigned by Industry Partners 
        for more information about third-party CVEs in the Security Update Guide. [3]


MITIGATION

        It is advised to update Edge to the latest release.


REFERENCES

        [1] Google Chrome Releases
            https://chromereleases.googleblog.com/2021

        [2] Security Update Guide
            https://msrc.microsoft.com/update-guide

        [3] Security Update Guide Supports CVEs Assigned by Industry Partners
            https://msrc-blog.microsoft.com/2021/01/13/security-update-guide-supports-cves-assigned-by-industry-partners/

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYXIQxuNLKJtyKPYoAQh6vQ//XwSboMXlKptsFvALcWdWwxhM84fMZPxD
j/CdyaqUUeA+w64RoDljxnWpyhZ3IgC01ePz9Wd9EoCZoHz54Td/rFmVpoWxHPCO
39irEX5g9B7QgHFd/25CZJ+Pft2/1Ytof5gYv7WSbsPyaOY8Ul7XR6I7neX+V6yN
8JrUHGTSgMe7PfAhTDTQjKE6CJQDWRjqZ5u4KZaMXP4Mmm+JHE49GwWrZj6xLkKp
R80e2wcGCITa4N7At1yIUIZjJq31YLVRhEraOMfm+qVWp/EQcOEjlTNFU3KH5aOd
w0DAKqhfHkDbAv+Qxl75GgUZlw5nNRLEOvFlgTTM5AXfZFZELIN7PXHCmXbxxR83
puprQdR9UMVypqblkBOTGV1NIcVuLMbKviNqiyXLiwxFWvvO2JYFjM3uZoOtnjz7
scOMa7wgQANyJ7kmwa/oe5CF1txVHXPXorVJVMDs0U+0Y5cTxH0kN15R4hjIUW7J
SABGuF/t1Blf5s2q6Dfp62YeaLyfjGJId/v1rHHeREiEoWzdJEjAezkWetADcOXS
CwIt71pnjwyIrHOtTN/oQPiBMDz8Hju5V++rQuYcyOytIaBTMBw/3g+XMm9jJLO2
cqMijzf8lzrl4fhZMooCaucu/WoyYbNVygmKoNcNGe57dlmKjLfcQtwafADEJXTY
Ftd5ELZco/4=
=TdbE
-----END PGP SIGNATURE-----