In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
2020-07-17T20:15:11.447
2024-11-21T05:06:14.100
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | westerndigital | wd_discovery | < 4.0.251.0 | Yes |
Application | westerndigital | wd_discovery | < 4.0.251.0 | Yes |