« Volver al listado

CVE-2024-39904

Estado: AplazadaAlta (8.8)—

VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system. A crafted URI can be used in a note to perform this attack using file:/// as a link. For example, file:///C:/WINDOWS/system32/cmd.exe. This allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as file:///C:/WINDOWS/system32/cmd.exe and file:///C:/WINDOWS/system32/calc.exe. This vulnerability can be exploited by creating and sharing specially crafted notes. An attacker could send a crafted note file and perform further attacks. This vulnerability is fixed in 3.18.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-39904",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-39904",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-11T18:24:26.515359Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "vnotex",
          "product": "vnote",
          "versions": [
            {
              "status": "affected",
              "version": "< 3.18.1"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:vnotex:vnote:*:*:*:*:*:*:*:*"
          ],
          "vendor": "vnotex",
          "product": "vnote",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.18.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-07-11T16:15:04.860",
  "references": [
    {
      "url": "https://github.com/vnotex/vnote/commit/3477469b669708ff547037fda9fc2817870428aa",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/vnotex/vnote/security/advisories/GHSA-vhh5-8wcv-68gj",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/vnotex/vnote/commit/3477469b669708ff547037fda9fc2817870428aa",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/vnotex/vnote/security/advisories/GHSA-vhh5-8wcv-68gj",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-73"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system. A crafted URI can be used in a note to perform this attack using file:/// as a link. For example, file:///C:/WINDOWS/system32/cmd.exe. This allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as file:///C:/WINDOWS/system32/cmd.exe and file:///C:/WINDOWS/system32/calc.exe. This vulnerability can be exploited by creating and sharing specially crafted notes. An attacker could send a crafted note file and perform further attacks. This vulnerability is fixed in 3.18.1."
    },
    {
      "lang": "es",
      "value": "VNote es una plataforma para tomar notas. Antes de la versión 3.18.1, existía una vulnerabilidad de ejecución de código en VNote, que permitía a un atacante ejecutar programas arbitrarios en el sistema de la víctima. Se puede usar un URI manipulado en una nota para realizar este ataque usando file:/// como enlace. Por ejemplo, archivo:///C:/WINDOWS/system32/cmd.exe. Esto permite a los atacantes ejecutar programas arbitrarios incorporando una referencia a un archivo ejecutable local como file:///C:/WINDOWS/system32/cmd.exe y file:///C:/WINDOWS/system32/calc.exe. Esta vulnerabilidad se puede aprovechar creando y compartiendo notas especialmente manipuladas. Un atacante podría enviar un archivo de nota manipulado y realizar más ataques. Esta vulnerabilidad se solucionó en 3.18.1."
    }
  ],
  "lastModified": "2026-06-17T07:42:59.860",
  "sourceIdentifier": "security-advisories@github.com"
}