CVE-2021-30605Improper Authentication in Google Chrome OS Readiness Tool

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5google/chromeunspecified1.0.2.0

🔴Vulnerability Details

1
GHSA
GHSA-x867-pp5j-mgrh: Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 12022-05-24