Popular web app framework allows remote code execution

By
Follow google news

Slack, Skype, Signal, Node JS Package Manager, Shopify affected.

A serious vulnerability in the Electron framework, which underpins many web apps such as Slack, Skype and Signal, could be exploited to allow attackers to run malicious code on victim computers.

Popular web app framework allows remote code execution

The vulnerability affects Electron.js apps running on Windows. Apps on Apple's macOS operating system or Linux distributions are not impacted.

Electron has patched the remote code execution vulnerability in the latest versions of the framework, and is urging developers to update their applications.

Attackers can take advantage of the flaw by abusing Electron apps that register themselves as the default handler for a protocol, such as slack://.

This means users who click on specially crafted links could inadvertently run malicious code that can be used for information leakage as well as to deploy ransomware.

Microsoft's Skype communications app and the Visual Studio Code editor are also affected by the vulnerability.

Slack version 3.0.3 and the latest version of Skype for Windows have been patched against the flaw.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Austrade to replace its data centre core network

Austrade to replace its data centre core network

Log In

  |  Forgot your password?