CVE-2024-8258

low

Description

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.

References

https://www.electronjs.org/docs/latest/tutorial/fuses

https://nvd.nist.gov/vuln/detail/CVE-2023-50643

https://nvd.nist.gov/vuln/detail/CVE-2023-49314

https://github.com/r3ggi/electroniz3r

Details

Source: Mitre, NVD

Published: 2024-09-10

Updated: 2024-09-27

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 2

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L

Severity: Low