Electron Builder Vulnerability Affects Windows Installers
CVE-2024-27303

7.3HIGH

Key Information:

Vendor
CVE Published:
6 March 2024

What is CVE-2024-27303?

The electron-builder product is susceptible to a command execution vulnerability specifically in the Windows NSIS installer. This issue arises due to NSExec's behavior of initially searching for cmd.exe in the same directory as the installer. An attacker could exploit this by placing a malicious executable named cmd.exe in that directory, leading to the unintentional execution of the malicious file when the installer runs. The vulnerability is present in electron-builder versions before 24.13.2, which has addressed the flaw. Unfortunately, no workaround exists that would mitigate the risk without upgrading to the fixed version.

Affected Version(s)

electron-builder < 24.13.2

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.