CVE-2024-43373
J4k0xb
CVE-2024-43373: An arbitrary file write vulnerability exists in the webcrack module. Processing malicious code, particularly when unpacking bundles and saving on Windows, allows attackers to overwrite files. This path traversal vulnerability lets attackers write arbitrary .js
files, potentially hijacking Node.js modules for arbitrary code execution. While the CVSS score is 7.8 (High), the SOCRadar Vulnerability Risk Score (SVRS) of 70 indicates a significant risk, though not critical, warranting prompt attention. Update to version 2.14.1 immediately to mitigate this security risk. This vulnerability is significant because successful exploitation could lead to complete system compromise through malicious code injection.
Description
CVE-2024-43373 is an arbitrary file write vulnerability in the webcrack module, triggered when using the unpack bundles feature in conjunction with the saving feature. An attacker can exploit this to overwrite files on the host system, allowing them to write arbitrary .js
files and potentially hijack legitimate Node.js modules for arbitrary code execution.
Key Insights
- SVRS Score: 30 (Moderate)
- Exploit Status: Active exploits have been published.
- CISA Warning: The Cybersecurity and Infrastructure Security Agency (CISA) has warned of the vulnerability, calling for immediate and necessary measures.
- In The Wild: The vulnerability is actively exploited by hackers.
Mitigation Strategies
- Update webcrack to version 2.14.1 or later.
- Restrict access to the webcrack module to authorized users only.
- Implement input validation to prevent malicious code from being processed.
- Monitor systems for suspicious activity and take appropriate action if necessary.
Additional Information
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.