CVE-2024-7979: Insufficient data validation in Installer
Chromium: CVE-2024-7979 Insufficient data validation in Installer
Other sources
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7979?
CVE-2024-7979 is classified as a high severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2024-7979?
To resolve CVE-2024-7979, users should update their Microsoft Edge or Google Chrome browsers to version 128.0.6613.84 or later.
Which versions of Microsoft Edge are affected by CVE-2024-7979?
CVE-2024-7979 affects Microsoft Edge versions up to, but not including, 128.0.2739.42.
What types of software are impacted by CVE-2024-7979?
CVE-2024-7979 impacts Chromium-based browsers, specifically Microsoft Edge and Google Chrome.
Is Microsoft Windows vulnerable due to CVE-2024-7979?
No, Microsoft Windows itself is not vulnerable due to CVE-2024-7979; the vulnerability affects the browsers running on Windows.