CVE-2019-13702: High severity google chrome (trace event) vulnerability
Published Nov 25, 2019
·Updated
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.
Affected Software
2 affected components
Google Chrome<78.0.3904.70
openSUSE Backports=15.0-sp1
Event History
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What access and user interaction are required to exploit this issue?
An attacker needs local access to the Windows system and must get a user to interact with a crafted executable. The issue does not require prior privileges.
2
Which systems are affected?
The affected component is the Google Chrome installer on Windows in versions prior to 78.0.3904.70. The provided software listing also includes openSUSE Backports, but does not specify affected package versions or configurations.
3
What is the likely impact of successful exploitation?
Successful exploitation can allow privilege escalation. The CVSS vector indicates high impact to confidentiality, integrity, and availability.