The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  




Advisories
Source ID Title
EUVD EUVD EUVD-2023-12202 The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  
Fixes

Solution

Weintek recommends users to implement the following mitigation techniques:·         Upgrade EasyBuilder Pro to v6.07.02.480 https://dl.weintek.com/EBPro/Installer/EBproV60702480.zip , v6.08.01.350 https://dl.weintek.com/EBPro/Installer/EBproV60801350.zip or later. ·         Use Decompile only on trusted sources and only when needed.


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:55:59.469Z

Reserved: 2023-01-06T18:50:05.156Z

Link: CVE-2023-0104

cve-icon Vulnrichment

Updated: 2024-08-02T05:02:43.504Z

cve-icon NVD

Status : Modified

Published: 2023-02-22T21:15:11.207

Modified: 2024-11-21T07:36:33.640

Link: CVE-2023-0104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.