Vulnerability Description
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Td | Advanced Dashboard | <= 3.0.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/khronokernel/2598c067d0f49b0f0a4c8b01cf129d34Third Party Advisory
- https://newsroom.ripeda.com/tag/macs-for-business/Broken Link
- https://www.electronjs.org/blog/statement-run-as-node-cvesIssue Tracking
- https://gist.github.com/khronokernel/2598c067d0f49b0f0a4c8b01cf129d34Third Party Advisory
- https://newsroom.ripeda.com/tag/macs-for-business/Broken Link
- https://www.electronjs.org/blog/statement-run-as-node-cvesIssue Tracking
FAQ
What is CVE-2023-50975?
CVE-2023-50975 is a vulnerability with a CVSS score of 8.4 (HIGH). The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in p...
How severe is CVE-2023-50975?
CVE-2023-50975 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-50975?
Check the references section above for vendor advisories and patch information. Affected products include: Td Advanced Dashboard.