First published: Wed May 16 2012(Updated: )
Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gain privileges via a Trojan horse plug-in in an unspecified directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =12.1 | |
Google Chrome (Trace Event) | <=19.0.1084.45 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3098 is classified as a medium severity vulnerability due to potential privilege escalation through a Trojan horse plug-in.
To fix CVE-2011-3098, update Google Chrome to version 19.0.1084.46 or later.
CVE-2011-3098 affects all versions of Google Chrome prior to 19.0.1084.46.
Yes, CVE-2011-3098 can be exploited by local users to gain privileges through a malicious plug-in.
CVE-2011-3098 primarily affects Google Chrome on Windows operating systems prior to version 19.0.1084.46.