VulnerabilityModified
CVE-2021-30605
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
HIGH 7.8EPSS 0.12%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- google/chrome os readiness tool
- Source
- chrome-cve-admin@google.com
References
- https://bit.ly/37CS6G9Third Party Advisory
- https://crbug.com/1240952Permissions Required
- https://bit.ly/37CS6G9Third Party Advisory
- https://crbug.com/1240952Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.