TROYANOSYVIRUS
Back to CVEs

CVE-2020-11614

HIGH
8.1

Description

Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a man-in-the-middle attack against this connection and replace executable files with malicious versions, which the operating system then executes under the context of the user running Hero Designer.

CVE Details

CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published6/11/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

mids\'_reborn_hero_designer_project:mids\'_reborn_hero_designer

Weaknesses (CWE)

CWE-319CWE-345

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.