In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.
References
History

Fri, 31 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 17 Jan 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Phiewer
Phiewer phiewer
Weaknesses CWE-426
CPEs cpe:2.3:a:phiewer:phiewer:4.1.0:*:*:*:*:*:*:*
Vendors & Products Phiewer
Phiewer phiewer
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 15 Jan 2025 23:00:00 +0000

Type Values Removed Values Added
Description In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-31T20:23:07.435Z

Reserved: 2024-11-20T00:00:00.000Z

Link: CVE-2024-53407

cve-icon Vulnrichment

Updated: 2025-01-16T16:33:23.637Z

cve-icon NVD

Status : Modified

Published: 2025-01-15T23:15:09.263

Modified: 2025-01-31T21:15:10.213

Link: CVE-2024-53407

cve-icon Redhat

No data.