Impact
The vulnerability lies in the updater component of Time4 Popcorn for Windows, MacOS, and Android, where a remote attacker can supply a malicious update that is executed by updater.exe on Windows or PT.updd on MacOS. Exploitation would allow arbitrary code execution on the target system, giving the attacker full control and the ability to install malware, exfiltrate data, or disrupt services. The weakness applies to the code that processes update files, corresponding to CWE-494.
Affected Systems
Time4 Popcorn for Windows versions 6.2.1.18 and earlier, Time4Popcorn for MacOS versions 6.2.1.17 and earlier, and Time4Popcorn for Android versions 3.5.0.173 and earlier.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while an EPSS score of less than 1% suggests that few active exploits are known. The vulnerability is not listed in the CISA KEV catalog. Given that the flaw can be triggered by remotely delivering a malicious update, any system that accepts updates without additional validation is at risk. Attackers can execute code without requiring user interaction, making the issue especially alarmingly convenient for threat actors.
OpenCVE Enrichment