EXPOSURES › CVE-2017-5030
CVE-2017-5030
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory corruption vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
CVE-2017-5030 represents a significant risk for DIB organizations relying on Chromium-based browsers, potentially enabling attackers to execute arbitrary code on user systems. This impacts NIST 800-171 controls related to data protection and incident response; immediate patching and vulnerability scanning are critical. Failure to address this could lead to data compromise and regulatory penalties.
Shame score — The vulnerability's exploitation in the wild and potential for remote code execution demonstrate a serious security oversight by a major vendor, impacting a widely used product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |