VulnerabilityAnalyzed
CVE-2017-5030
Google Chromium V8 Memory Corruption Vulnerability
KEVHIGH 8.8EPSS 41.7%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 41.69% probability · 99th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-125
- Affected
- google/chrome · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- chrome-cve-admin@google.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-5030
References
- http://rhn.redhat.com/errata/RHSA-2017-0499.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3810Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96767Broken Link, Third Party Advisory, VDB Entry
- https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.htmlRelease Notes, Vendor Advisory
- https://crbug.com/682194Exploit, Issue Tracking
- https://security.gentoo.org/glsa/201704-02Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-126/Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2017-0499.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3810Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/96767Broken Link, Third Party Advisory, VDB Entry
- https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.htmlRelease Notes, Vendor Advisory
- https://crbug.com/682194Exploit, Issue Tracking
- https://security.gentoo.org/glsa/201704-02Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-126/Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5030US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.