code.google.comConfirmation
http://code.google.com/p/chromium/issues/detail?id=130276 CVE-2012-2764
Google Chrome 19.0.1084.52 - 'metro_driver.dll' DLL Loading Arbitrary Code Execution
Record summary
CVE-2012-2764 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGoogle Chrome 19.0.1084.52 - 'metro_driver.dll' DLL Loading Arbitrary Code ExecutionExploitDB exploitby Moshe ZioniNot analyzed1 file
References
4googlechromereleases.blogspot.comConfirmation
http://googlechromereleases.blogspot.com/2012/06/stable-channel-update_26.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-2764 oval:org.mitre.oval:def:15375vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15375