An ability to process crash dumps under root privileges and inappropriate symlinks handling could lead to a local privilege escalation in Crash Reporting in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to perform privilege escalation via a crafted HTML page.
References
Configurations
History
No history.
Information
Published : 2019-01-09 19:29
Updated : 2023-11-07 02:39
NVD link : CVE-2017-15404
Mitre link : CVE-2017-15404
CVE.ORG link : CVE-2017-15404
JSON object : View
Products Affected
- chrome
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition