VDB
CVE-2021-30605
CVE-2021-30605
PUBLISHED
CVSS 7.800000190734863 HIGH
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
EPSS 0.12% · 2.0th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
2.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | unspecified | |
| chrome_os_readiness_tool | 0 |
Timeline
- Sep 8, 2021 CVE Published
- Sep 9, 2021 EPSS Score
- Sep 16, 2021 EPSS Score
- Nov 6, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 25, 2022 EPSS Score
- Oct 19, 2022 EPSS Score
- Dec 16, 2022 EPSS Score
References
- https://crbug.com/1240952 technical
- https://bit.ly/37CS6G9 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-30605 advisory