CVE-2024-39698 is a high-severity vulnerability affecting Electron applications using electron-updater on Windows, allowing for the execution of malicious updates due to a flaw in signature validation. An attacker can trick the verifySignature() function into validating a different file's certificate by exploiting environment variable expansion in command-line arguments. This requires a compromised update manifest (e.g., server compromise or MiTM) and user interaction, leading to high impact on confidentiality, integrity, and availability. While no active exploits or public exploit code are currently known, and community discussion is minimal, a patch is available in electron-updater 6.3.0-alpha.6 and later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.3.0CPE matchmatch criteria | cpe:2.3:a:electron:electron-builder:*:*:*:*:*:node.js:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:a:electron:electron-builder:6.3.0:alpha0:*:*:*:node.js:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:a:electron:electron-builder:6.3.0:alpha1:*:*:*:node.js:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:a:electron:electron-builder:6.3.0:alpha2:*:*:*:node.js:*:* | ||
6.3.0CPE matchmatch criteria | cpe:2.3:a:electron:electron-builder:6.3.0:alpha3:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.