PT-2021-7163 · Yandex · Yandex Browser

Xi-Tauw

·

Published

2021-01-15

·

Updated

2022-06-24

·

CVE-2021-25261

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yandex Browser versions prior to 22.5.0.862
Description The issue is related to errors in processing symbolic links when loading the installation file, which can allow an attacker to elevate their privileges. A local, low-privileged attacker can exploit this to execute arbitrary code with SYSTEM privileges by manipulating symlinks to the installation file during the Yandex Browser update process.
Recommendations For versions prior to 22.5.0.862, update to version 22.5.0.862 or later to resolve the issue. As a temporary workaround, consider restricting access to the installation file and update process to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03534
CVE-2021-25261

Affected Products

Yandex Browser