PT-2024-19401 · Unknown · Creditcoin

Dobermann-Pinscher

·

Published

2024-01-17

·

Updated

2024-01-26

·

CVE-2024-22410

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Creditcoin (affected versions not specified)
Description The issue concerns the Windows binary of the Creditcoin node, which loads a suite of DLLs provided by Microsoft at startup. If a malicious user has access to overwrite the program files directory, it is possible to replace these DLLs and execute arbitrary code. The vulnerable DLL files are from the Windows networking subsystem, the Visual C++ runtime, and low-level cryptographic primitives. The blockchain development team views the threat posed by a hypothetical binary planting attack as minimal and represents a low-security risk. The team also states that running Creditcoin on Windows is officially unsupported and should be thought of as experimental.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2024-22410
GHSA-CX5C-XWCV-VHMQ

Affected Products

Creditcoin