Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
References
Link | Resource |
---|---|
https://bit.ly/37CS6G9 | Third Party Advisory |
https://crbug.com/1240952 | Permissions Required |
https://bit.ly/37CS6G9 | Third Party Advisory |
https://crbug.com/1240952 | Permissions Required |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://bit.ly/37CS6G9 - Third Party Advisory | |
References | () https://crbug.com/1240952 - Permissions Required |
Information
Published : 2021-09-08 21:15
Updated : 2024-11-21 06:04
NVD link : CVE-2021-30605
Mitre link : CVE-2021-30605
CVE.ORG link : CVE-2021-30605
JSON object : View
Products Affected
microsoft
- windows_10
- windows_8.1
- windows_7
- chrome_os_readiness_tool
CWE
CWE-287
Improper Authentication