PT-2024-40896 · Microsoft+2 · Windows+2
Published
2024-01-03
·
Updated
2024-01-03
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
gratient version 0.5
Description
The issue concerns malicious code embedded in the library, which targets Windows platforms. This code is capable of harvesting information and credentials from the user's system and sending them to a remote server. Services that may be affected include Mullvad VPN and Telegram.
Recommendations
For version 0.5, avoid using the gradient library until a clean version is available, and consider removing the current version to prevent potential data harvesting. As a temporary workaround, consider restricting access to sensitive information on systems where this library is used.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mullvad Vpn
Telegram
Windows