CVE-2023-2939: Insufficient data validation in Installer
Chromium: CVE-2023-2939 Insufficient data validation in Installer
Other sources
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-2939?
CVE-2023-2939 has been classified as a high severity vulnerability in Chromium-based browsers.
How do I fix CVE-2023-2939?
To address CVE-2023-2939, update Google Chrome or Microsoft Edge to the latest version available.
Which applications are affected by CVE-2023-2939?
CVE-2023-2939 affects Google Chrome versions prior to 114.0.5735.90 and Microsoft Edge versions prior to 114.0.1823.37.
What causes the vulnerability CVE-2023-2939?
CVE-2023-2939 is caused by insufficient data validation in Chromium, leading to potential security issues.
Are other operating systems affected by CVE-2023-2939?
CVE-2023-2939 affects the Chromium-based browsers running on Windows, Linux, and potentially other operating systems.