CVE-2024-39698: Code Signing Bypass on Windows in electron-updater < 6.3.0-alpha.6

Published Jul 9, 2024
·
Updated

Observations The file packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts implements the signature validation routine for Electron applications on Windows. It executes the following command in a new shell (process.env.ComSpec on Windows, usually C:\Windows\System32\cmd.exe):

https://github.com/electron-userland/electron-builder/blob/140e2f0eb0df79c2a46e35024e96d0563355fc89/packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts#L35-L41

Because of the surrounding shell, a first pass by cmd.exe expands any environment variable found in command-line above.

Exploitation

This creates a situation where verifySignature() can be tricked into validating the certificate of a different file than the one that was just downloaded. If the step is successful, the malicious update will be executed even if its signature is invalid.

Impact

This attack assumes a compromised update manifest (server compromise, Man-in-the-Middle attack if fetched over HTTP, Cross-Site Scripting to point the application to a malicious updater server, etc.).

Patch

This vulnerability was patched in #8295, by comparing the path in the output of Get-AuthenticodeSignature with the intended one. The patch is available starting from 6.3.0-alpha.6.

Other sources

electron-updater allows for automatic updates for Electron apps. The file packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts implements the signature validation routine for Electron applications on Windows. Because of the surrounding shell, a first pass by cmd.exe expands any environment variable found in command-line above. This creates a situation where verifySignature() can be tricked into validating the certificate of a different file than the one that was just downloaded. If the step is successful, the malicious update will be executed even if its signature is invalid. This attack assumes a compromised update manifest (server compromise, Man-in-the-Middle attack if fetched over HTTP, Cross-Site Scripting to point the application to a malicious updater server, etc.). The patch is available starting from 6.3.0-alpha.6.

MITRE

Affected Software

8 affected componentsFixes available
npm/electron-updater<=6.3.0-alpha.5
6.3.0-alpha.6
Electron Electron-builder Node.js<6.3.0
Electron Electron-builder Node.js=6.3.0-alpha0
Electron Electron-builder Node.js=6.3.0-alpha1
Electron Electron-builder Node.js=6.3.0-alpha2
Electron Electron-builder Node.js=6.3.0-alpha3
Electron Electron-builder Node.js=6.3.0-alpha4
Electron Electron-builder Node.js=6.3.0-alpha5

Event History

Jul 9, 2024
Advisory Published
via GitHub·05:48 PM
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-39698?

CVE-2024-39698 has been classified with a critical severity due to its potential for code execution in Electron applications on Windows.

2

How do I fix CVE-2024-39698?

To mitigate CVE-2024-39698, upgrade the electron-updater package to version 6.3.0-alpha.6 or later.

3

Which versions are affected by CVE-2024-39698?

CVE-2024-39698 affects electron-updater versions up to 6.3.0-alpha.5 and specific alpha versions of electron-builder.

4

What components does CVE-2024-39698 impact?

CVE-2024-39698 primarily impacts the electron-updater package during the signature validation process for Electron applications.

5

Is there any workaround for CVE-2024-39698?

While upgrading is the recommended fix for CVE-2024-39698, users can temporarily disable signature validation as a workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203