NONE · 0

CVE-2024-22169

WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any ...

Vulnerability Description

WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresses this issue by disabling certain features and fuses in Electron. The attack vector for this issue requires the victim to have the WD Discovery app installed on their device.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-22169?

CVE-2024-22169 is a documented vulnerability. WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any ...

How severe is CVE-2024-22169?

CVSS scoring is not yet available for CVE-2024-22169. Check NVD for updates.

Is there a patch for CVE-2024-22169?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.