Vulnerability Description
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandex | Yandex Browser | < 21.9.0.390 |
Related Weaknesses (CWE)
References
- https://yandex.com/bugbounty/i/hall-of-fame-browser/Vendor Advisory
- https://yandex.com/bugbounty/i/hall-of-fame-browser/Vendor Advisory
FAQ
What is CVE-2021-25263?
CVE-2021-25263 is a vulnerability with a CVSS score of 7.8 (HIGH). Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files ...
How severe is CVE-2021-25263?
CVE-2021-25263 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25263?
Check the references section above for vendor advisories and patch information. Affected products include: Yandex Yandex Browser.