Security Vulnerability in Western Digital’s WD Discovery App Enables Unauthorized Code Execution

The WD Discovery application, a prominent name in storage solutions, has been found to have a security flaw designated as CVE 2024-22169, which carries a CVSS base score of 7.1. This vulnerability poses a risk of unauthorized code execution.

The root of the problem lies in the Node.js configuration within the WD Discovery app. The use of the ELECTRON_RUN_AS_NODE environment variable could potentially facilitate the execution of arbitrary code. Specifically, this flaw permits code execution within the context of the WD Discovery application, and can be exploited by any malicious software running with standard user permissions.

According to the company, “Any malicious software with regular user rights can exploit this flaw to execute code within the WD Discovery app’s context.”

The issue was brought to attention by Yoko Kho, AbdulKarim, and Fahad Alamri from the HakTrak Cybersecurity Team. This vulnerability impacts users of WD Discovery Desktop App versions prior to 5.0.589 on both Windows and macOS platforms.

Update Recommended

Western Digital advises users to promptly update their WD Discovery app to version 5.0.589 or newer for both Windows and Mac systems.

Version 5.0.589 addresses the problem by “disabling certain Electron features and protections.”

Users can acquire the latest version from the WD Discovery Downloads page, enable automatic updates, or follow the guidance provided in the WD Discovery Online User Guide.

More Articles & Posts