CVE-2024-53407

In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.
References
Link Resource
https://github.com/SyFi/CVE-2024-53407 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:phiewer:phiewer:4.1.0:*:*:*:*:*:*:*

History

17 Jan 2025, 22:51

Type Values Removed Values Added
First Time Phiewer phiewer
Phiewer
CWE CWE-426
Summary
  • (es) En Phiewer 4.1.0, una inyección de dylib conduce a la ejecución de comandos que permite a los atacantes inyectar un archivo dylib, lo que potencialmente conduce al control remoto y al acceso no autorizado a datos confidenciales del usuario.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CPE cpe:2.3:a:phiewer:phiewer:4.1.0:*:*:*:*:*:*:*
References () https://github.com/SyFi/CVE-2024-53407 - () https://github.com/SyFi/CVE-2024-53407 - Third Party Advisory

15 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 23:15

Updated : 2025-01-17 22:51


NVD link : CVE-2024-53407

Mitre link : CVE-2024-53407

CVE.ORG link : CVE-2024-53407


JSON object : View

Products Affected

phiewer

  • phiewer
CWE
CWE-426

Untrusted Search Path