PT-2022-19505 · Electron · Electron

Marshallofsound

·

Published

2022-06-13

·

Updated

2022-06-27

·

CVE-2022-29257

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electron versions prior to 18.0.0-beta.6 Electron versions prior to 17.2.0 Electron versions prior to 16.2.6 Electron versions prior to 15.5.5
Description A vulnerability in Electron allows attackers who have control over a given app's update server or update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto-updating infrastructure, and the ease of that attack entirely depends on the potential victim's infrastructure security.
Recommendations Update to Electron version 18.0.0-beta.6 or later Update to Electron version 17.2.0 or later Update to Electron version 16.2.6 or later Update to Electron version 15.5.5 or later There are no known workarounds for this issue, so updating to a patched version of Electron is necessary.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29257
GHSA-77XC-HJV8-WW97

Affected Products

Electron