PUREVPN
X

Can you allow arbitrary code execution – Patch Google Chrome now

PureVPN

The CIS Advisory reported that Google Chrome has several security issues. These severe vulnerabilities could allow hackers to run code on a person’s computer. If a hacker can exploit these vulnerabilities successfully, they could take control of the computer and install programs, access or delete files, or create new user accounts with complete control. People who use 

Chrome with fewer privileges or permissions on their computers may be less affected than those with administrative access.

Technical details

The never exploited vulnerabilities with the greatest threat are:

Tactic: Initial Access (TA0001):
Technique: Drive-By Compromise (T1189):

Source: NIST

What arbitrary code executions could do?

If a hacker gets you through this arbitrary code execution, he can:

Who’s most affected?

Government: 

Large and medium government entities: HIGH

Small entities: MEDIUM

Businesses:

Large and medium business entities: HIGH

Small business entities: MEDIUM

Home Users: LOW

Emergency update to fix a zero-day vulnerability

Steps you must take to be safe

Source: CyberArk

Source: Google

Source: Research Gate

What did we learn?

Educating and informing users about the risks associated with hypertext links in emails or attachments, especially from untrusted sources, is very important.  Reminding them to avoid visiting untrusted websites or clicking on links provided by unknown or untrusted sources is also essential. 

Organizations must establish and maintain a security awareness program to educate the workforce on secure interactions with enterprise assets and data. Conduct training at the time of hiring and at least once a year. Review and update the program’s content annually or when significant enterprise changes occur. 

Be safe!

Categories:
Tags:
Leave Comment