Electron Builder Vulnerability Affects Windows Installers
CVE-2024-27303
7.3HIGH
What is CVE-2024-27303?
The electron-builder product is susceptible to a command execution vulnerability specifically in the Windows NSIS installer. This issue arises due to NSExec's behavior of initially searching for cmd.exe in the same directory as the installer. An attacker could exploit this by placing a malicious executable named cmd.exe in that directory, leading to the unintentional execution of the malicious file when the installer runs. The vulnerability is present in electron-builder versions before 24.13.2, which has addressed the flaw. Unfortunately, no workaround exists that would mitigate the risk without upgrading to the fixed version.
Affected Version(s)
electron-builder < 24.13.2
