Description


Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.

References


https://bit.ly/37CS6G9

Third Party Advisory

https://crbug.com/1240952

Permissions Required

Weaknesses



CWE-287

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2021-09-08T21:15:10.243

3 years ago

Last modified

2021-09-15T15:58:32.900

3 years ago