Impact
An update mechanism in Time4 Popcorn for Windows, MacOS, and Android allows a remote attacker to run arbitrary code on the target system. The flaw resides in the updater executable (updater.exe on Windows, PT.updd on MacOS) and can be triggered by an attacker who can cause the updater to execute without user intervention. If exploited, the attacker could gain full control of the affected machine, install malicious software, or exfiltrate data, leading to a complete compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Time4 Popcorn for Windows versions 6.2.1.18 and earlier, Time4Popcorn for MacOS up to 6.2.1.17, and Time4Popcorn for Android through 3.5.0.173. Users running these specific releases should verify their version and be aware that any omitted patches create a risk vector.
Risk and Exploitability
No CVSS score is publicly available, and the EPSS score is not listed, suggesting limited public exploitation data at this time. The vulnerability is not in the CISA KEV catalog. However, the lack of a known exploit does not mitigate the risk, as the flaw allows remote code execution without user interaction, making it highly attractive to adversaries. Attackers could leverage the updater to spawn arbitrary code, potentially compromising the device or network.
OpenCVE Enrichment