CVE-2022-0799: Insufficient policy enforcement in Installer
Published Dec 12, 2021
·Updated
Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.
Credit
Abdelhamid Naceri (halov)
Affected Software
5 affected componentsFixes available
Google Chrome<99.0.4844.51
99.0.4844.51
Google Chrome<99.0.4844.51
macOS
Linux Linux Kernel
Microsoft Windows
Event History
Dec 12, 2021
CVE Published
12:00 AM
Apr 5, 2022
CVE Published
via MITRE·12:25 AM
Data Sourced
via MITRE·12:25 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-0799.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allow…'.
3
What is the severity of CVE-2022-0799?
The severity of CVE-2022-0799 is high (8.8).
4
How does this vulnerability affect Google Chrome on Windows?
This vulnerability affects Google Chrome on Windows prior to version 99.0.4844.51.
5
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by using a crafted offline installer file to perform local privilege escalation.