Vulnerability Description
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os Readiness Tool | < 1.0.2.0 | |
| Microsoft | Windows 10 | - |
| Microsoft | Windows 7 | - |
| Microsoft | Windows 8.1 | - |
Related Weaknesses (CWE)
References
- https://bit.ly/37CS6G9Third Party Advisory
- https://crbug.com/1240952Permissions Required
- https://bit.ly/37CS6G9Third Party Advisory
- https://crbug.com/1240952Permissions Required
FAQ
What is CVE-2021-30605?
CVE-2021-30605 is a vulnerability with a CVSS score of 7.8 (HIGH). Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary acc...
How severe is CVE-2021-30605?
CVE-2021-30605 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30605?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome Os Readiness Tool, Microsoft Windows 10, Microsoft Windows 7, Microsoft Windows 8.1.