Korean
<< Back
VID 28912
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description The version of Google Chrome installed on the remote Windows host is prior to 71.0.3578.98. It is, therefore, affected by a use after free vulnerability in pdfium. This could allow a remote attacker to potentially exploit heap corruption via a crafted pdf file as noted in Google Chrome stable channel update release notes for 2018/12/12.
Please refer to the release notes for additional information.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop_12.html

* Platforms Affected:
Google Chrome versions prior to 71.0.3578.98
Microsoft Windows Any version
Recommendation Upgrade to the latest version Google Chrome (71.0.3578.98 or later), available from the Google Web site at http://www.google.com/chrome/
Related URL CVE-2018-17481 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)