CRITICAL🇵🇱 Wersja polska

CVE-2024-7824

CVSS 9.8v3.1pub. 2024-10-03upd. 2024-10-30

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

🤖 AI Analysis
How it works

The error consists of improper data type handling in the wrUrl.Dll library — the component accesses a resource using an incompatible type (Access of Resource Using Incompatible Type). This type of error can lead to unpredictable application behavior, including unintended code execution or bypass of protection mechanisms. The vulnerability is remotely exploitable without authentication and without user interaction (vector AV:N/AC:L/PR:N/UI:N).

Impact

An attacker can remotely abuse the functionality of the Web Shield component, which according to the CVSS vector can result in complete loss of confidentiality, integrity, and availability of the protected system.

Mitigation & patch

Webroot SecureAnywhere Web Shield should be updated to version 2.1.2.3 or newer. Detailed information is available in the vendor's knowledge base under solution identifier 4275.

Who is affected

Webroot SecureAnywhere - Web Shield in versions prior to 2.1.2.3 on Windows platforms in ARM, 64-bit, and 32-bit architectures (wrUrl.Dll module).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Webroot Secureanywhere Web Shield

    APP
    Webroot
    < 2.1.2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-7825CRITICAL9.8PL ✓same product

Type Confusion w Webroot SecureAnywhere Web Shield – RCE bez autoryzacji

CVE-2024-7826CRITICAL9.8PL ✓same product

Webroot SecureAnywhere Web Shield — błędna obsługa wyjątków umożliwia nadużycie funkcjonalności

CVE-2020-5754CRITICAL9.1PL ✓same vendor

Type confusion w Webroot Endpoint Agents umożliwia odczyt pamięci lub crash

CVE-2018-4012CRITICAL9.0PL ✓same vendor

Buffer overflow w Webroot BrightCloud SDK — RCE przez nagłówki HTTP

CVE-2020-5755HIGH7.8same vendor

Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory a...