Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Vulnerability detected through Microsoft Defender #643

Open
chewgun opened this issue Apr 16, 2024 · 4 comments
Open

New Vulnerability detected through Microsoft Defender #643

chewgun opened this issue Apr 16, 2024 · 4 comments

Comments

@chewgun
Copy link

chewgun commented Apr 16, 2024

Hello,

We just saw today (as we installed Greenshot), a vulnerability about Pippo.

Severity level is critical

Summary: Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict unmarshalling.

Impact: If a threat were to exploit this vulnerability, they could execute arbitrary code on the system, potentially leading to unauthorized access, data breaches, and further compromise of the affected system.

Remediation: Upgrade to Pippo version 1.11.1 or later.

More Details can be found here:
https://nvd.nist.gov/vuln/detail/CVE-2018-18240
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

@awvtti
Copy link

awvtti commented Apr 16, 2024

We also encountered this today.

@awvtti
Copy link

awvtti commented Apr 16, 2024

It seem the Pippo we have is part of the app Greenshot. Greenshot has not been updated since 2017.

@Lakritzator
Copy link

Greenshot is a .NET application and doesn't use Java or Pippo, this can only be a false positive from defender.

@jklingen
Copy link

JFYI it has been brought to our attention that

Microsoft added the Pippo inaccuracy to the list of updated vulnerabilities.
Vulnerability support in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management

I hope that the Defender alerts will disappear as a result.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants