Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12174 | Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://yandex.com/bugbounty/i/hall-of-fame-browser/ |
|
History
No history.
Status: PUBLISHED
Assigner: yandex
Published:
Updated: 2024-08-03T19:56:11.179Z
Reserved: 2021-01-15T00:00:00.000Z
Link: CVE-2021-25263
No data.
Status : Modified
Published: 2021-08-17T19:15:08.103
Modified: 2024-11-21T05:54:38.477
Link: CVE-2021-25263
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD