CVE-2014-3196
high
CVSS v3
—
VIR risk
7.5
Description
base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| chrome | {"endIncluding":"38.0.2125.7"} | |
References
- http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
- http://www.securityfocus.com/bid/70273
- https://crbug.com/338538
- https://src.chromium.org/viewvc/chrome?revision=285195&view=revision
- https://src.chromium.org/viewvc/chrome?revision=288152&view=revision
- http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
- http://www.securityfocus.com/bid/70273
- https://crbug.com/338538
- https://src.chromium.org/viewvc/chrome?revision=285195&view=revision
- https://src.chromium.org/viewvc/chrome?revision=288152&view=revision
CWEs
CWE-264
💬 Discuss CVE-2014-3196 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.