CVE-2014-3196
published 2014-10-08CVE-2014-3196: base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which…
PriorityP430high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.00%
59.3th percentile
base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 38.0.2125.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w95r-8w92-vggw: base/memory/shared_memory_win
ghsa_unreviewed·2022-05-17
CVE-2014-3196 [HIGH] GHSA-w95r-8w92-vggw: base/memory/shared_memory_win
base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
Project0
Did the “Man With No Name” Feel Insecure? - Project Zero
project_zero·2014-10-01·CVSS 7.5
CVE-2014-3196 [HIGH] Did the “Man With No Name” Feel Insecure? - Project Zero
Posted by James Forshaw, Taker of Names
Sometimes when I'm doing security research I'll come across a bug which surprises me. I discovered just such a bug in the Windows version of Chrome which exposed a little-known security detail in the OS. The bug, CVE-2014-3196 was fixed in M38, so it seemed a good time for a blog post. The actual reported issue is here. While the bug didn’t allow for a full sandbox escape it did provide the initial part of a chain; something that’s still important to fix.
The security of an OS kernel is of extreme importance to modern user-mode sandboxes such as is used in Chrome. Some OS kernels have built-in facilities for reducing the attack surface of the kernel and the OS in general, for example seccomp on Linux or the sandbox facilities in OS X. While not a
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://www.securityfocus.com/bid/70273https://crbug.com/338538https://src.chromium.org/viewvc/chrome?revision=285195&view=revisionhttps://src.chromium.org/viewvc/chrome?revision=288152&view=revisionhttp://googlechromereleases.blogspot.com/2014/10/stable-channel-update.htmlhttp://www.securityfocus.com/bid/70273https://crbug.com/338538https://src.chromium.org/viewvc/chrome?revision=285195&view=revisionhttps://src.chromium.org/viewvc/chrome?revision=288152&view=revision
2014-10-08
Published