Collected research
Signature Validation Bypass Leading to RCE In Electron-Updater
Shows that an attacker-controlled Electron update filename can break the PowerShell command used for signature validation. The resulting parse error is handled as successful validation, while the same interpolation point can also permit command injection and execution of a malicious update.
Record
- Researcher
- Luca Carettoni and Lorenzo Stella
- Published by
- Doyensec
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Luca Carettoni and Lorenzo Stella, first published at the original source. Preserved copies are kept so the citation survives its host.