CVE-2024-42366

CRITICAL

VRCX < 2024.03.23 - Remote Code Execution via CefSharp Browser Over-Permission and XSS

Title source: llm
STIX 2.1

Description

VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be combined to result in remote command execution. These vulnerabilities are patched in VRCX 2023.12.24. In addition to the patch, VRCX maintainers worked with the VRC team and blocked the older version of VRCX on the VRC's API side. Users who use the older version of VRCX must update their installation to continue using VRCX.

Scores

CVSS v3 9.0
EPSS 0.0074
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-79
Status published
Products (1)
vrcx-team/vrcx < 2024.03.23
Published Aug 08, 2024
Tracked Since Feb 18, 2026