electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
The vulnerability encompasses three classes of errors: CWE-94 (improper neutralization of directives in generated code — code injection), CWE-732 (improper permissions on critical resources), and CWE-940 (improper verification of source of a communication channel). An attacker with local access and low privileges can, without user interaction, exploit these errors to inject and execute their own code in the context of the application and affect external systems.
An attacker can gain complete access to the confidentiality, integrity, and availability of both the targeted system and systems associated with it (high impact on SC/SI/SA components). In practice, this may mean SSH/RDP/VNC session hijacking, credential theft, and execution of arbitrary code.
Update electerm to version 3.9.0, in which the vulnerability has been fixed. Details of the fix are available in the project's GitHub repository (commit 0599e67) and in the security advisory GHSA-7p5m-v798-f8vv.
The electerm application in versions 3.0.6 to 3.8.8 (inclusive)
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XElecterm Project Electerm
APPElecterm Project3.0.6 – 3.9.0 (excl.)
Related vulnerabilities
RCE w Electerm — brak walidacji protokołu URL w handlerze hiperłączy
Command injection w electerm — wykonanie kodu przez złośliwe releaseInfo.name
Command injection w Electerm — wstrzyknięcie polecenia przez zdalny ciąg wersji
RCE w electerm — wykonanie kodu przez deep links i spreparowane skróty
Wykonanie dowolnego kodu w Electerm przez niezweryfikowane żądanie do usługi