CVE-2024-27303: electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)

Published Mar 4, 2024
·
Updated

Impact Windows-Only: The NSIS installer makes a system call to open cmd.exe via NSExec in the .nsh installer script. NSExec by default searches the current directory of where the installer is located before searching PATH. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file.

Patches Fixed in https://github.com/electron-userland/electron-builder/pull/8059

Workarounds None, it executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.

References https://cwe.mitre.org/data/definitions/426.html https://cwe.mitre.org/data/definitions/427

Other sources

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the .nsh installer script. NSExec by default searches the current directory of where the installer is located before searching PATH. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file. Version 24.13.2 fixes this issue. No known workaround exists. The code executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.

MITRE

Affected Software

3 affected componentsFixes available
npm/app-builder-lib<24.13.2
24.13.2
All of the following
Electron Electron-builder Node.js<24.13.2
Microsoft Windows

Event History

Mar 4, 2024
Advisory Published
via GitHub·08:42 PM
Mar 6, 2024
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-27303?

CVE-2024-27303 has a severe impact on Windows systems due to the risk of executing arbitrary commands via a compromised installer.

2

How do I fix CVE-2024-27303?

To fix CVE-2024-27303, update the app-builder-lib package to version 24.13.2 or later.

3

What software is affected by CVE-2024-27303?

The affected software includes the app-builder-lib package and versions of Electron Builder up to 24.13.2.

4

What type of vulnerability is CVE-2024-27303?

CVE-2024-27303 is a command execution vulnerability introduced through the NSIS installer system call.

5

Is CVE-2024-27303 specific to any operating system?

Yes, CVE-2024-27303 specifically affects Windows operating systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203