← Back

CVE-2020-6574

nvd nist
Published: Sep 21, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.

Affected (8)

Products: Google: Chrome · Opensuse: Backports Sle, Leap · Debian: Debian Linux · +1 more
Show all products
1 product
Chrome
2 products
Backports Sle
Leap
1 product
Debian Linux
1 product
Fedora
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 85.0.4183.102
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0 sp1
Version 15.0 sp2
Opensuse
Version 15.1
Version 15.2
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Fedoraproject
Version 31
Version 33

References (18)

Source: chrome-cve-admin@google.com
Mailing ListPatchThird Party Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: chrome-cve-admin@google.com
Release NotesVendor Advisory
Source: chrome-cve-admin@google.com
Permissions RequiredVendor Advisory
Source: chrome-cve-admin@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.