City
Epaper

CERT-In warns users of multiple bugs in Google Chrome, Zoho software

By IANS | Updated: July 7, 2022 15:05 IST

New Delhi, July 7 The Indian Computer Emergency Response Team (CERT-In), which comes under the IT Ministry, has ...

Open in App

New Delhi, July 7 The Indian Computer Emergency Response Team (CERT-In), which comes under the IT Ministry, has warned users of multiple vulnerabilities in Google Chrome which could allow a remote attacker to execute arbitrary code and denial-of-service (DoS) conditions on the targeted system.

A remote attacker could exploit these vulnerabilities by sending specially crafted requests on the targeted system.

"Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and denial-of-service (DoS) conditions on the targeted system," said CERT-In the advisory late on Wednesday.

These vulnerabilities exist in Google Chrome due to 'Heap Buffer' overflow in 'WebRTC', 'Type Confusion in V8' and 'Use after Free' in Chrome OS Shell.

The vulnerability (CVE-2022-2294) is being exploited in the wild, said the cyber agency, adding that the users are advised to apply patches urgently.

CERT-In also advised users against a 'Remote Code Execution' vulnerability that has been reported in a Zoho Corporation software which could be exploited by an unauthenticated remote attacker to execute arbitrary code on the targeted system.

This vulnerability exists in 'Zoho ManageEngine ADAudit Plus' due to a 'misconfigured XML' parser that processes user-supplied input without sufficient validation.

"Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the targeted system," warned the cyber agency, advising the users to upgrade to the latest Zoho 'ManageEngine ADAudit Plus' security build update.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Secure ShellgoogleWord on macWho dgMicrosoft incUs google & youtubeSk duaDan patelBacPrivate institutesStory of reality tv
Open in App

Related Stories

TechnologyGoogle Birthday Doodle: Search Engine Giant Brings Back 1998 Logo as It Turns 27 Today

NationalPrayagraj: UPSC Aspirant Attempts Sex Change After Google Search, Hospitalized in Critical Condition

FootballEnglish Premier League 2025-26 Google Doodle: Search Engine Giant Celebrates Start of Season With Football-Themed

MumbaiCyber Fraud in Mumbai: Elderly Woman Loses Rs 98,202 After Calling Fake Customer Care Number Found on Internet

NationalBITS Pilani Placement 2025: Over 80% Students Placed, Average Salary Rises to Rs 19.4 Lakh

International Realted Stories

InternationalSouth Korea: Ex-Prez Yoon absent from insurrection trial for 13th consecutive session

InternationalOutrage after photos show ex-B'desh minister handcuffed to hospital bed before his death

InternationalIndia, France hold 22nd "Air Staff Talks" to strengthen military cooperation

InternationalIndia rips Pakistan over its hypocrisy on human rights, calls it " a country with worst record"

InternationalIndian missions worldwide mark Gandhi Jayanti with tributes, hymns and Swachhata drives