First published: Mon Apr 25 2016(Updated: )
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Atom Electron | <=0.33.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1202 is categorized as a medium severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2016-1202, update Atom Electron to version 0.33.5 or later.
CVE-2016-1202 is an untrusted search path vulnerability affecting Atom Electron.
Users running Atom Electron versions prior to 0.33.5 are at risk from CVE-2016-1202.
An attacker exploiting CVE-2016-1202 can gain elevated privileges by using a malicious Node.js module located in a parent directory.