PT-2020-14319 · Wire · Wire

Benjamin Altpeter

·

Published

2020-10-16

·

Updated

2020-10-28

·

CVE-2020-15258

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wire versions prior to 3.20.x
Description The issue allows an attacker to execute code on the victim's machine by sending messages containing links with arbitrary protocols. The victim must interact with the link and sees the URL that is opened. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 3.20.x, update to Wire 3.20.x to resolve the issue. As a temporary workaround, consider avoiding interaction with links from untrusted sources until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15258
GHSA-5GPX-9976-GGPM

Affected Products

Wire