PT-2024-19401 · Unknown · Creditcoin
Dobermann-Pinscher
·
Published
2024-01-17
·
Updated
2024-01-26
·
CVE-2024-22410
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Creditcoin (affected versions not specified)
Description
The issue concerns the Windows binary of the Creditcoin node, which loads a suite of DLLs provided by Microsoft at startup. If a malicious user has access to overwrite the program files directory, it is possible to replace these DLLs and execute arbitrary code. The vulnerable DLL files are from the Windows networking subsystem, the Visual C++ runtime, and low-level cryptographic primitives. The blockchain development team views the threat posed by a hypothetical binary planting attack as minimal and represents a low-security risk. The team also states that running Creditcoin on Windows is officially unsupported and should be thought of as experimental.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Creditcoin