VulnerabilityAnalyzed
CVE-2024-8258
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.
LOW 2.0EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- logitech/logi options\+
- Source
- cve-coordination@logitech.com
References
- https://github.com/r3ggi/electroniz3rExploit, Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-49314Not Applicable
- https://nvd.nist.gov/vuln/detail/CVE-2023-50643Not Applicable
- https://www.electronjs.org/docs/latest/tutorial/fusesProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.