webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module name includes a path traversal sequence with Windows path separators, an attacker can exploit this to overwrite files on the host system. This vulnerability allows an attacker to write arbitrary `.js` files to the host system, which can be leveraged to hijack legitimate Node.js modules to gain arbitrary code execution. This vulnerability has been patched in version 2.14.1.
History

Fri, 16 Aug 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:j4k0xb:webcrack:*:*:*:*:*:node.js:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Thu, 15 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared J4k0xb
J4k0xb webcrack
CPEs cpe:2.3:a:j4k0xb:webcrack:*:*:*:*:*:*:*:*
Vendors & Products J4k0xb
J4k0xb webcrack
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Aug 2024 14:45:00 +0000

Type Values Removed Values Added
Description webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifically crafted malicious code on Windows systems. This vulnerability is triggered when using the unpack bundles feature in conjunction with the saving feature. If a module name includes a path traversal sequence with Windows path separators, an attacker can exploit this to overwrite files on the host system. This vulnerability allows an attacker to write arbitrary `.js` files to the host system, which can be leveraged to hijack legitimate Node.js modules to gain arbitrary code execution. This vulnerability has been patched in version 2.14.1.
Title webcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious Bundle
Weaknesses CWE-20
CWE-22
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-15T14:31:34.120Z

Updated: 2024-08-15T15:55:26.684Z

Reserved: 2024-08-09T14:23:55.513Z

Link: CVE-2024-43373

cve-icon Vulnrichment

Updated: 2024-08-15T15:55:18.633Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-15T15:15:21.217

Modified: 2024-08-16T21:46:08.440

Link: CVE-2024-43373

cve-icon Redhat

No data.