QID 983064
QID 983064: Dotnet (nuget) Security Update for CefSharp.Wpf.HwndHost (GHSA-gvqv-779r-4jgp)
CVE-2020-16017: Use after free in site isolation
- https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16017
Google is aware of reports that exploits for CVE-2020-16013 and CVE-2020-16017 exist in the wild.
There is currently little to no public information on the issue other than it has been flagged as `High` severity.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gvqv-779r-4jgp for updates pertaining to this vulnerability.
Vendor References
- GHSA-gvqv-779r-4jgp -
github.com/advisories/GHSA-gvqv-779r-4jgp
CVEs related to QID 983064
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gvqv-779r-4jgp | CefSharp.Common |
|
|
| GHSA-gvqv-779r-4jgp | CefSharp.WinForms |
|
|
| GHSA-gvqv-779r-4jgp | CefSharp.Wpf |
|
|
| GHSA-gvqv-779r-4jgp | CefSharp.Wpf.HwndHost |
|