VulnerabilityModified
CVE-2017-15392
Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.
MEDIUM 4.3EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/chrome · debian/debian linux
- Source
- chrome-cve-admin@google.com
References
- http://www.securityfocus.com/bid/101482
- https://access.redhat.com/errata/RHSA-2017:2997
- https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
- https://crbug.com/714401
- https://security.gentoo.org/glsa/201710-24
- https://www.debian.org/security/2017/dsa-4020
- http://www.securityfocus.com/bid/101482
- https://access.redhat.com/errata/RHSA-2017:2997
- https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
- https://crbug.com/714401
- https://security.gentoo.org/glsa/201710-24
- https://www.debian.org/security/2017/dsa-4020
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.