PT-2024-22281 · Easyrange · Easyrange
Published
2024-03-26
·
Updated
2024-08-02
·
CVE-2024-28131
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EasyRange Ver 1.41
Description
The issue with the executable file search path when displaying an extracted file on Explorer may lead to loading an executable file that resides in the same folder where the extracted file is placed. If this issue is exploited, arbitrary code may be executed with the privilege of the running program. The developer was unreachable, and users should consider stopping the use of EasyRange Ver 1.41.
Recommendations
For EasyRange Ver 1.41, consider stopping the use of this version as the developer is unreachable and no fix is available. As a temporary workaround, consider restricting access to the executable file search path to minimize the risk of exploitation. Avoid using EasyRange Ver 1.41 to display extracted files on Explorer until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easyrange