PT-2018-17496 · Electrum · Electrum

Bauerj

·

Published

2018-01-27

·

Updated

2018-02-15

·

CVE-2018-6353

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electrum versions 2.9.4 and earlier Electrum versions 3.0.5 and earlier
Description The issue allows attackers to steal Bitcoin by executing arbitrary Python code, potentially through social-engineering attacks where a user pastes code they do not understand, or through code pasted by a physically proximate attacker at an unattended workstation. This code can run at a later time when the wallet password has been entered, allowing for unauthorized access.
Recommendations For Electrum versions 2.9.4 and earlier, update to a version later than 2.9.4 to resolve the issue. For Electrum versions 3.0.5 and earlier, update to a version later than 3.0.5 to resolve the issue. As a temporary workaround, consider disabling the Python console feature until a patch is available. Restrict access to the workstation when the wallet is open to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6353

Affected Products

Electrum