Vulnerabilities > CVE-2012-2764 - Unspecified vulnerability in Google Chrome

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
google
microsoft
nessus
exploit available

Summary

Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.

Vulnerable Configurations

Part Description Count
Application
Google
2338
OS
Microsoft
1

Exploit-Db

descriptionGoogle Chrome 19.0.1084.52 'metro_driver.dll' DLL Loading Arbitrary Code Execution Vulnerability. CVE-2012-2764. Remote exploit for windows platform
idEDB-ID:37510
last seen2016-02-04
modified2012-06-26
published2012-06-26
reporterMoshe Zioni
sourcehttps://www.exploit-db.com/download/37510/
titleGoogle Chrome 19.0.1084.52 - 'metro_driver.dll' DLL Loading Arbitrary Code Execution Vulnerability

Nessus

NASL familyWindows
NASL idGOOGLE_CHROME_20_0_1132_43.NASL
descriptionThe version of Google Chrome installed on the remote host is earlier than 20.0.1132.43 and is, therefore, affected by the following vulnerabilities : - An error exists related to the loading of the
last seen2020-06-01
modified2020-06-02
plugin id59735
published2012-06-27
reporterThis script is Copyright (C) 2012-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/59735
titleGoogle Chrome < 20.0.1132.43 Multiple Vulnerabilities

Oval

accepted2013-08-12T04:07:28.995-04:00
classvulnerability
contributors
  • nameShane Shaffer
    organizationG2, Inc.
  • nameShane Shaffer
    organizationG2, Inc.
  • nameMaria Kedovskaya
    organizationALTX-SOFT
definition_extensions
commentGoogle Chrome is installed
ovaloval:org.mitre.oval:def:11914
descriptionUntrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.
familywindows
idoval:org.mitre.oval:def:15375
statusaccepted
submitted2012-06-27T11:45:52.000-04:00
titleUntrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows
version44

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/114779/googlechrome-dllhijack.txt
idPACKETSTORM:114779
last seen2016-12-05
published2012-07-17
reporterMoshe Zioni
sourcehttps://packetstormsecurity.com/files/114779/Google-Chrome-19-metro_driver.dll-Mishandling.html
titleGoogle Chrome 19 metro_driver.dll Mishandling