CVE-2020-14049
A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password cracking.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password cracking. NOTE: this issue exists because of an incomplete fix for CVE-2019-12569.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- rakuten/viber
- Source
- cve@mitre.org
References
- https://jeffs.sh/CVEs/CVE-2020-14049.txtExploit, Mitigation, Third Party Advisory
- https://www.viber.com/en/security/Vendor Advisory
- https://jeffs.sh/CVEs/CVE-2020-14049.txtExploit, Mitigation, Third Party Advisory
- https://www.viber.com/en/security/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.