// For flags

CVE-2012-2764

Google Chrome 19.0.1084.52 - 'metro_driver.dll' DLL Loading Arbitrary Code Execution

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.

Vulnerabilidad de path de búsqueda no confiable en Google Chrome anteriores a v20.0.1132.43 en Windows podría permitir a usuario locales obtener privilegios a través de un troyano Metro DLL en el directorio de trabajo actual.

Google Chrome developers, while trying to be adaptive and current, added some windows 8 helper functions to aid the development of Metro style behavior, but does not include the library file itself, thus resulting in an unqualified dynamic-link library call to 'metro_driver.dll'. A user with local disk access can carefully construct a DLL that suits the pattern that is being traversed by the client and implement it somewhere along the search path and the client will load it seamlessly.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-18 CVE Reserved
  • 2012-06-26 First Exploit
  • 2012-06-27 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
<= 20.0.1132.42
Search vendor "Google" for product "Chrome" and version " <= 20.0.1132.42"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.0
Search vendor "Google" for product "Chrome" and version "20.0.1132.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.1
Search vendor "Google" for product "Chrome" and version "20.0.1132.1"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.2
Search vendor "Google" for product "Chrome" and version "20.0.1132.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.3
Search vendor "Google" for product "Chrome" and version "20.0.1132.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.4
Search vendor "Google" for product "Chrome" and version "20.0.1132.4"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.5
Search vendor "Google" for product "Chrome" and version "20.0.1132.5"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.6
Search vendor "Google" for product "Chrome" and version "20.0.1132.6"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.7
Search vendor "Google" for product "Chrome" and version "20.0.1132.7"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.8
Search vendor "Google" for product "Chrome" and version "20.0.1132.8"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.9
Search vendor "Google" for product "Chrome" and version "20.0.1132.9"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.10
Search vendor "Google" for product "Chrome" and version "20.0.1132.10"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.11
Search vendor "Google" for product "Chrome" and version "20.0.1132.11"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.12
Search vendor "Google" for product "Chrome" and version "20.0.1132.12"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.13
Search vendor "Google" for product "Chrome" and version "20.0.1132.13"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.14
Search vendor "Google" for product "Chrome" and version "20.0.1132.14"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.15
Search vendor "Google" for product "Chrome" and version "20.0.1132.15"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.16
Search vendor "Google" for product "Chrome" and version "20.0.1132.16"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.17
Search vendor "Google" for product "Chrome" and version "20.0.1132.17"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.18
Search vendor "Google" for product "Chrome" and version "20.0.1132.18"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.19
Search vendor "Google" for product "Chrome" and version "20.0.1132.19"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.20
Search vendor "Google" for product "Chrome" and version "20.0.1132.20"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.21
Search vendor "Google" for product "Chrome" and version "20.0.1132.21"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.22
Search vendor "Google" for product "Chrome" and version "20.0.1132.22"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.23
Search vendor "Google" for product "Chrome" and version "20.0.1132.23"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.24
Search vendor "Google" for product "Chrome" and version "20.0.1132.24"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.25
Search vendor "Google" for product "Chrome" and version "20.0.1132.25"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.26
Search vendor "Google" for product "Chrome" and version "20.0.1132.26"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.27
Search vendor "Google" for product "Chrome" and version "20.0.1132.27"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.28
Search vendor "Google" for product "Chrome" and version "20.0.1132.28"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.29
Search vendor "Google" for product "Chrome" and version "20.0.1132.29"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.30
Search vendor "Google" for product "Chrome" and version "20.0.1132.30"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.31
Search vendor "Google" for product "Chrome" and version "20.0.1132.31"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.32
Search vendor "Google" for product "Chrome" and version "20.0.1132.32"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.33
Search vendor "Google" for product "Chrome" and version "20.0.1132.33"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.34
Search vendor "Google" for product "Chrome" and version "20.0.1132.34"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.35
Search vendor "Google" for product "Chrome" and version "20.0.1132.35"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.36
Search vendor "Google" for product "Chrome" and version "20.0.1132.36"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.37
Search vendor "Google" for product "Chrome" and version "20.0.1132.37"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.38
Search vendor "Google" for product "Chrome" and version "20.0.1132.38"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.39
Search vendor "Google" for product "Chrome" and version "20.0.1132.39"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.40
Search vendor "Google" for product "Chrome" and version "20.0.1132.40"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe
Google
Search vendor "Google"
Chrome
Search vendor "Google" for product "Chrome"
20.0.1132.41
Search vendor "Google" for product "Chrome" and version "20.0.1132.41"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
*-
Safe