#VU7958 Backdoor in Web Paint (Chrome extension)

 

#VU7958 Backdoor in Web Paint (Chrome extension)

Published: August 16, 2017 / Updated: November 22, 2018


Vulnerability identifier: #VU7958
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: N/A
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Web Paint (Chrome extension)
Software vendor:
liang.zhou2276

Description

The vulnerability allows a remote attacker to gain unauthorized access to victim's browser.

The vulnerability exists due to presence of backdoor code in Web Paint Google Chrome extension 1.2.1, distributed via Google Web Store.



Remediation

Update to version 1.2.2 or later.

External links