CVE-2021-37969: Inappropriate implementation in Google Updater
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 118.0.5993.70-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 118.0.5993.70-1~deb12u1Fixed in 118.0.5993.70-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 94.0.4606.54 - Upgrade
Upgrade
Google Chrome (Google Updater)to a version that resolves this vulnerability.Fixed in 94.0.4606.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-37969.
What is the affected software?
Google Chrome on Windows versions prior to 94.0.4606.54.
How does this vulnerability occur?
This vulnerability occurs due to inappropriate implementation in Google Updater in Google Chrome.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by performing local privilege escalation via a crafted file.
How can I fix this vulnerability?
To fix this vulnerability, update Google Chrome on Windows to version 94.0.4606.54 or later.