PT-2024-40533 · Microsoft+2 · Windows+2
Published
2024-08-30
·
Updated
2024-08-30
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
gratient version 0.5
Description:
The issue concerns a user-facing library used for generating color gradients of text, which contained obfuscated, malicious code in version 0.5. This malicious code targets Windows platforms, harvesting information and credentials from the user's system and sending them to a remote server. Services that may be affected include Mullvad VPN and Telegram.
Recommendations:
For version 0.5, avoid using this version of the gradient library to prevent potential information and credential harvesting. As a temporary workaround, consider restricting access to sensitive information on systems where this library is used until a safe version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mullvad Vpn
Telegram
Windows