CVE-2021-30605

Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
References
Link Resource
https://bit.ly/37CS6G9 Third Party Advisory
https://crbug.com/1240952 Permissions Required
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome_os_readiness_tool:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-09-08 21:15

Updated : 2024-02-28 18:48


NVD link : CVE-2021-30605

Mitre link : CVE-2021-30605

CVE.ORG link : CVE-2021-30605


JSON object : View

Products Affected

google

  • chrome_os_readiness_tool

microsoft

  • windows_8.1
  • windows_7
  • windows_10
CWE
CWE-287

Improper Authentication