CVE-2024-39904
Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system. A crafted URI can be used in a note to perform this attack using file:/// as a link. For example, file:///C:/WINDOWS/system32/cmd.exe. This allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as file:///C:/WINDOWS/system32/cmd.exe and file:///C:/WINDOWS/system32/calc.exe. This vulnerability can be exploited by creating and sharing specially crafted notes. An attacker could send a crafted note file and perform further attacks. This vulnerability is fixed in 3.18.1.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.66% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-73
- Source
- security-advisories@github.com
References
- https://github.com/vnotex/vnote/commit/3477469b669708ff547037fda9fc2817870428aa
- https://github.com/vnotex/vnote/security/advisories/GHSA-vhh5-8wcv-68gj
- https://github.com/vnotex/vnote/commit/3477469b669708ff547037fda9fc2817870428aa
- https://github.com/vnotex/vnote/security/advisories/GHSA-vhh5-8wcv-68gj
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.