CVE-2021-46702
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occurs because the product doesn't properly free memory.
Tor Browser versión 9.0.7 en Windows 10 build 10586, es vulnerable a una divulgación de información. Esto podría permitir a atacantes locales omitir la función de anonimato prevista y obtener información sobre los servicios onion visitados por un usuario local. Esto puede lograrse al analizar memoria RAM incluso varias horas después de que el usuario local haya usado el producto. Esto ocurre porque el producto no libera apropiadamente la memoria.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-26 CVE Reserved
- 2022-02-26 CVE Published
- 2022-02-26 First Exploit
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-404: Improper Resource Shutdown or Release
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.sciencedirect.com/science/article/pii/S0167404821001358 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/Exmak-s/CVE-2021-46702 | 2022-02-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 9.0.7 Search vendor "Torproject" for product "Tor" and version "9.0.7" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|