Description
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
Related CPE's
Vulnerable
References
Third Party Advisory
Permissions Required
Third Party Advisory
Permissions Required
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-08T19:15:10.243Z
4 years agoLast modified
2024-11-21T05:04:16.610Z
1 year ago