CVE-2021-25261: High severity yandex browser vulnerability
Published Jun 15, 2022
·Updated
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Affected Software
2 affected components
Yandex Yandex Browser<22.5.0.862
Microsoft Windows
Event History
Jun 15, 2022
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25261?
CVE-2021-25261 is considered a local privilege escalation vulnerability.
2
How do I fix CVE-2021-25261?
To mitigate CVE-2021-25261, upgrade Yandex Browser to version 22.5.0.862 or later.
3
Who is affected by CVE-2021-25261?
CVE-2021-25261 affects users of Yandex Browser for Windows prior to version 22.5.0.862.
4
What type of attack is possible with CVE-2021-25261?
CVE-2021-25261 allows low-privileged attackers to execute arbitrary code with SYSTEM privileges.
5
When was CVE-2021-25261 discovered?
CVE-2021-25261 was identified and documented in 2021.