CVE-2024-22169 - CVE House
Back to Database
Status published High CVE-2024-22169

Misconfiguration in node.js causing a code execution in WD Discovery

Vulnerability Description

WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresses this issue by disabling certain features and fuses in Electron. The attack vector for this issue requires the victim to have the WD Discovery app installed on their device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-22169

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Western Digital would like to thank YoKo Kho, Fahad Alamri, and AbdulKarim from HakTrak Cybersecurity Squad for reporting this issue

Affected Vendor

Western Digital

View all reports →

Affected Software

WD Discovery
Vulnerable Versions:
0

Timeline

Official Publish: August 2nd, 2024
Last Modified: August 5th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)