Korean
<< Back
VID 28876
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Google Chrome which is older than 27.0.1453.116 has been installed on the host. Google Chrome is a web browser released by Google. Google Chrome versions prior to 27.0.1453.116 are vulnerable to Flash Click-Jacking.

- affected by a click-jacking vulnerability due to the embedded Flash plugin.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://code.google.com/p/chromium/issues/detail?id=249335
http://googlechromereleases.blogspot.kr/2013/06/stable-channel-update_18.html

* Platforms Affected:
Google Chrome versions prior to 27.0.1453.116
Microsoft Windows Any version
Recommendation Upgrade to the latest version Google Chrome (27.0.1453.116 or later), available from the Google Web site at http://www.google.com/chrome/
Related URL CVE-2013-2866 (CVE)
Related URL 61046,61047,61049,61050,61051,61052,61053,61054,61055,61056,61057,61058,61059,61060,61061 (SecurityFocus)
Related URL (ISS)