==================================================================== CERT-Renater Note d'Information No. 2020/VULN298 _____________________________________________________________________ DATE : 22/05/2020 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Microsoft Edge (Chromium-based) versions prior to 83.0.478.37. ===================================================================== https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1195 _____________________________________________________________________ CVE-2020-1195 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Security Vulnerability Published: 05/21/2020 MITRE CVE-2020-1195 An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privileges. The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running. The security update addresses the vulnerability by modifying how Microsoft Edge (Chromium-based) Feedback extension validates files. Exploitability Assessment The following table provides an exploitability assessment for this vulnerability at the time of original publication. Publicly Disclosed Exploited Latest Software Release Older Software Release Denial of Service No No 2 - Exploitation Less Likely 4 - N/A N/A Security Updates To determine the support life cycle for your software version or edition, see the Microsoft Support Lifecycle. Product Platform Article Download Impact Severity Supersedence Microsoft Edge (Chromium-based) Elevation of Privilege Moderate Mitigations Microsoft has not identified any mitigating factors for this vulnerability. Workarounds Microsoft has not identified any workarounds for this vulnerability. FAQ What version of Microsoft Edge (Chromium-base) contains the fix for this vulnerability? The version that contains the update is 83.0.478.37. Acknowledgements David Erceg See acknowledgements for more information. Disclaimer The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. Revisions Version Date Description 1.0 05/21/2020 Information published. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================