Lucene search

K
cveGitHub_MCVE-2024-21640
HistoryJan 13, 2024 - 8:15 a.m.

CVE-2024-21640

2024-01-1308:15:07
CWE-125
GitHub_M
web.nvd.nist.gov
14
chromium embedded framework
cef
out-of-bounds read
sandbox bypass
cve-2024-21640
security vulnerability
nvd

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

18.0%

Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.CefVideoConsumerOSR::OnFrameCaptured does not check pixel_format properly, which leads to out-of-bounds read out of the sandbox. This vulnerability was patched in commit 1f55d2e.

Affected configurations

Nvd
Vulners
Node
chromiumembeddedchromium_embedded_frameworkRange<2024-01-05
VendorProductVersionCPE
chromiumembeddedchromium_embedded_framework*cpe:2.3:a:chromiumembedded:chromium_embedded_framework:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "chromiumembedded",
    "product": "cef",
    "versions": [
      {
        "version": "< commit 1f55d2e",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

18.0%

Related for CVE-2024-21640