PT-2024-21807 · Unknown · Electron-Builder

Bruno-1337

·

Published

2024-03-04

·

Updated

2025-12-03

·

CVE-2024-27303

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions electron-builder versions prior to 24.13.2
Description A vulnerability in electron-builder for Windows allows an attacker to execute a malicious file named cmd.exe if it is placed in the same folder as the installer. The NSIS installer makes a system call to open cmd.exe via NSExec in the .nsh installer script. NSExec searches the current directory before searching PATH, which enables the attack. This issue is fixed in version 24.13.2.
Recommendations For versions prior to 24.13.2, update to version 24.13.2 to resolve the issue. As a temporary workaround, consider avoiding the use of the NSIS installer until the update is applied. Restrict access to the installer folder to minimize the risk of exploitation. Avoid placing any executable files in the same folder as the installer.

Exploit

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2024-27303
GHSA-R4PF-3V7R-HH55
OPENSUSE-SU-2024:13782-1

Affected Products

Electron-Builder