7.2
CVSSv2

CVE-2012-2764

Published: 27/06/2012 Updated: 19/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Google Chrome prior to 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome 20.0.1132.17

google chrome 20.0.1132.6

google chrome 20.0.1132.9

google chrome 20.0.1132.21

google chrome 20.0.1132.0

google chrome 20.0.1132.29

google chrome 20.0.1132.40

google chrome 20.0.1132.39

google chrome 20.0.1132.18

google chrome 20.0.1132.19

google chrome 20.0.1132.14

google chrome 20.0.1132.7

google chrome 20.0.1132.4

google chrome 20.0.1132.22

google chrome 20.0.1132.23

google chrome 20.0.1132.30

google chrome 20.0.1132.31

google chrome 20.0.1132.15

google chrome 20.0.1132.12

google chrome 20.0.1132.13

google chrome 20.0.1132.5

google chrome 20.0.1132.10

google chrome 20.0.1132.24

google chrome 20.0.1132.3

google chrome 20.0.1132.25

google chrome 20.0.1132.26

google chrome 20.0.1132.36

google chrome 20.0.1132.35

google chrome 20.0.1132.32

google chrome 20.0.1132.38

google chrome 20.0.1132.37

google chrome 20.0.1132.41

google chrome

google chrome 20.0.1132.20

google chrome 20.0.1132.16

google chrome 20.0.1132.11

google chrome 20.0.1132.8

google chrome 20.0.1132.2

google chrome 20.0.1132.1

google chrome 20.0.1132.27

google chrome 20.0.1132.28

google chrome 20.0.1132.34

google chrome 20.0.1132.33

Exploits

/* source: wwwsecurityfocuscom/bid/54477/info Google Chrome is prone to a vulnerability that lets attackers execute arbitrary code An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Linked Library (DLL) ...
Google Chrome developers, while trying to be adaptive and current, added some windows 8 helper functions to aid the development of Metro style behavior, but does not include the library file itself, thus resulting in an unqualified dynamic-link library call to 'metro_driverdll' A user with local disk access can carefully construct a DLL that suit ...