Korean
<< Back
VID 28942
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The version of Google Chrome installed on the remote Windows host is prior to 108.0.5359.125. It is, therefore, affected by multiple vulnerabilities as referenced in the 2022_12_stable-channel-update-for-desktop_13 advisory.

- Use after free in Blink Media. (CVE-2022-4436)
- Use after free in Mojo IPC. (CVE-2022-4437)
- Use after free in Blink Frames. (CVE-2022-4438)
- Use after free in Aura. (CVE-2022-4439)
- Use after free in Profiles. (CVE-2022-4440)

* References:
https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html
https://crbug.com/1383991
https://crbug.com/1394692
https://crbug.com/1381871
https://crbug.com/1392661
https://crbug.com/1382761

* Platforms Affected:
Google Chrome versions prior to 108.0.5359.125
Microsoft Windows Any version
Recommendation Upgrade to the latest version Google Chrome (108.0.5359.125 or later), available from the Google Web site at http://www.google.com/chrome/
Related URL CVE-2022-4436,CVE-2022-4437,CVE-2022-4438,CVE-2022-4439,CVE-2022-4440 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)