CVE-2021-25263: High severity yandex browser vulnerability
Published Aug 17, 2021
·Updated
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
Affected Software
1 affected component
Yandex Yandex Browser Windows<21.9.0.390
Event History
Aug 17, 2021
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25263?
CVE-2021-25263 is classified as a local privilege escalation vulnerability.
2
How does CVE-2021-25263 allow arbitrary code execution?
CVE-2021-25263 allows arbitrary code execution by manipulating files in a directory with insecure permissions during the Yandex Browser update process.
3
Which versions of Yandex Browser are affected by CVE-2021-25263?
CVE-2021-25263 affects Yandex Browser versions prior to 21.9.0.390.
4
What steps should I take to mitigate CVE-2021-25263?
To mitigate CVE-2021-25263, update Yandex Browser to version 21.9.0.390 or later.
5
Is CVE-2021-25263 a widespread vulnerability?
CVE-2021-25263 specifically affects Yandex Browser and may not be widely known among users.