CVE-2024-27303: electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)
7.3
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.19096%
CWE
Published
3/4/2024
Updated
3/16/2024
KEV Status
No
Technology
JavaScript
Technical Details
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| app-builder-lib | npm | < 24.13.2 | 24.13.2 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from NSIS script commands using 'cmd' without full path in three locations. The patch explicitly replaces 'cmd' with '%SYSTEMROOT%\System32\cmd.exe' to enforce using the system's legitimate command interpreter. The affected code was in macros handling process management during installation, making them the vulnerable functions. High confidence comes from direct correlation between patched lines and CWE-426/CWE-427 descriptions.