CVE-2023-50975
HIGHTD Bank TD Advanced Dashboard < 3.0.3 - Remote Code Execution via Electron RunAsNode Misconfiguration
Title source: llmDescription
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.
References (3)
Core 3
Core References
Third Party Advisory
https://gist.github.com/khronokernel/2598c067d0f49b0f0a4c8b01cf129d34
Issue Tracking
https://www.electronjs.org/blog/statement-run-as-node-cves
Scores
CVSS v3
8.4
EPSS
0.0023
EPSS Percentile
13.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (1)
td/advanced_dashboard
< 3.0.3
Published
Feb 21, 2024
Tracked Since
Feb 18, 2026