First published: Wed Sep 08 2021(Updated: )
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
Credit: chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome OS Readiness Tool | <1.0.2.0 | |
Microsoft Windows 10 | ||
Microsoft Windows 7 | ||
Microsoft Windows 8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30605 has a moderate severity level, as it allows potential bypass of discretionary access controls.
To fix CVE-2021-30605, upgrade your Google Chrome OS Readiness Tool to version 1.0.2.0 or later.
CVE-2021-30605 affects the Google Chrome OS Readiness Tool installer on Windows versions prior to 1.0.2.0.
Yes, CVE-2021-30605 can potentially lead to unauthorized access or a security breach by loosening DCOM access rights.
Currently, the best workaround for CVE-2021-30605 is to avoid using the affected version of the Chrome OS Readiness Tool until it can be updated.