CVE-2018-1000006 is a critical remote code execution vulnerability affecting GitHub Electron applications running on Windows, specifically versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, and 1.6.15 and earlier. This flaw allows an attacker to execute arbitrary commands if a user clicks a specially crafted URL, leveraging a weakness in the protocol handler. With a CVSS score of 8.8 (High) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector and potential for complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available, including Metasploit modules, and it has garnered substantial community discussion and media coverage, though it is not currently listed on the CISA KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.2CPE matchmatch criteria | cpe:2.3:a:atom:electron:1.8.2:beta1:*:*:*:*:*:* | ||
1.8.2CPE matchmatch criteria | cpe:2.3:a:atom:electron:1.8.2:beta2:*:*:*:*:*:* | ||
1.8.2CPE matchmatch criteria | cpe:2.3:a:atom:electron:1.8.2:beta3:*:*:*:*:*:* | ||
<= 1.7.10CPE matchmatch criteria | cpe:2.3:a:atom:electron:*:*:*:*:*:*:*:* | ||
<= 1.6.15CPE matchmatch criteria | cpe:2.3:a:atom:electron:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.