Forum Discussion

AndrewSAIF's avatar
AndrewSAIF
Iron Contributor
Jul 12, 2022

Is the fix for CVE-2022-2294 contained in Extended Stable 102.0.1245.56?

Hi folks,

 

Can anyone tell me whether the fix for CVE-2022-2294 is contained in Extended Stable 102.0.1245.56? I assume that it would be, since the Stable Channel build that contains it came out on the same date, but it is not explicitly called out in the changelog. 

Thanks!

Andrew

4 Replies

  • Reza_Ameri's avatar
    Reza_Ameri
    Silver Contributor
    We recommend you update to the latest build to ensure all security updates are available and they and several issues have been fixed.
    However, it is available for Extended Stable: 102.0.1245.56 build too.
    Based on the following website:
    https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-2294
    • AndrewSAIF's avatar
      AndrewSAIF
      Iron Contributor

      Reza_Ameri 

       

      It looks like Microsoft has started documenting these security fixes in the changelog for Extended Stable. I noticed this when I went to check on a fix for https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3075. It is listed as explicitly being contained in 104.0.1293.81. 

      Just wanted to say that I appreciate Microsoft responding to our feedback and making this change. Thanks! 

       

      Andrew

  • AndrewSAIF's avatar
    AndrewSAIF
    Iron Contributor
    This news outlet seems to think this build contains the fix: https://www.theregister.com/2022/07/07/edge_cves/