CVE-2018-18354
published 2018-12-11CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.42%
70.2th percentile
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| debian | chromium | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| debian | debian_linux | — | — |
| chrome | < 71.0.3578.80 | 71.0.3578.80 | |
| chrome | >= unspecified < 71.0.3578.80 | 71.0.3578.80 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Insufficient data validation in Shell Integration
vendor_redhat·2018-12-04·CVSS 8.8
CVE-2018-18354 [HIGH] chromium-browser: Insufficient data validation in Shell Integration
chromium-browser: Insufficient data validation in Shell Integration
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
Debian
CVE-2018-18354: chromium - Insufficient validate of external protocols in Shell Integration in Google Chrom...
vendor_debian·2018·CVSS 8.8
CVE-2018-18354 [HIGH] CVE-2018-18354: chromium - Insufficient validate of external protocols in Shell Integration in Google Chrom...
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed in 71.0.3578.80-1)
GHSA
GHSA-g5c2-53mv-qgrh: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71
ghsa_unreviewed·2022-05-14
CVE-2018-18354 [HIGH] CWE-20 GHSA-g5c2-53mv-qgrh: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
OSV
CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71
osv·2018-12-11·CVSS 8.8
CVE-2018-18354 [HIGH] CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71
Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/889459https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/889459https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352
2018-12-11
Published