CVE-2024-22169: Misconfiguration in node.js causing a code execution in WD Discovery
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRONRUNASNODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresses this issue by disabling certain features and fuses in Electron. The attack vector for this issue requires the victim to have the WD Discovery app installed on their device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22169?
CVE-2024-22169 is classified as a high severity vulnerability due to its potential for code execution.
How do I fix CVE-2024-22169?
To mitigate CVE-2024-22169, users should upgrade WD Discovery to version 5.0.589 or later.
Who is affected by CVE-2024-22169?
CVE-2024-22169 affects users of WD Discovery versions prior to 5.0.589.
What types of attacks can exploit CVE-2024-22169?
CVE-2024-22169 can be exploited through malicious applications leveraging the 'ELECTRON_RUN_AS_NODE' environment variable.
Is CVE-2024-22169 specific to certain operating systems?
CVE-2024-22169 is primarily a concern for systems running WD Discovery with configurations that allow the exploitation of its Node.js environment.