#VU7957 Backdoor in Copyfish (Chrome extension)
Published: August 16, 2017 / Updated: November 22, 2018
Vulnerability identifier: #VU7957
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: N/A
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerable software:
Copyfish (Chrome extension)
Copyfish (Chrome extension)
Software vendor:
a9t9 software GmbH
a9t9 software GmbH
Description
The vulnerability allows a remote attacker to gain unauthorized access to victim's browser.
The vulnerability exists due to presence of backdoor code in Copyfish Google Chrome extension 2.8.5, distributed via Google Web Store.
The vulnerability exists due to presence of backdoor code in Copyfish Google Chrome extension 2.8.5, distributed via Google Web Store.
Remediation
Update to version 2.8.6 or later.