Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
The error consists of improper data type handling in the wrUrl.Dll library — the component accesses a resource using an incompatible type (Access of Resource Using Incompatible Type). This type of error can lead to unpredictable application behavior, including unintended code execution or bypass of protection mechanisms. The vulnerability is remotely exploitable without authentication and without user interaction (vector AV:N/AC:L/PR:N/UI:N).
An attacker can remotely abuse the functionality of the Web Shield component, which according to the CVSS vector can result in complete loss of confidentiality, integrity, and availability of the protected system.
Webroot SecureAnywhere Web Shield should be updated to version 2.1.2.3 or newer. Detailed information is available in the vendor's knowledge base under solution identifier 4275.
Webroot SecureAnywhere - Web Shield in versions prior to 2.1.2.3 on Windows platforms in ARM, 64-bit, and 32-bit architectures (wrUrl.Dll module).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWebroot Secureanywhere Web Shield
APPWebroot< 2.1.2.3
Related vulnerabilities
Type Confusion w Webroot SecureAnywhere Web Shield – RCE bez autoryzacji
Webroot SecureAnywhere Web Shield — błędna obsługa wyjątków umożliwia nadużycie funkcjonalności
Type confusion w Webroot Endpoint Agents umożliwia odczyt pamięci lub crash
Buffer overflow w Webroot BrightCloud SDK — RCE przez nagłówki HTTP
Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory a...