vendor:
Internet Download Manager
by:
M. Akil Gündogan
8.8
CVSS
HIGH
Remote Code Execution (RCE)
79
CWE
Product Name: Internet Download Manager
Affected Version From: v.6.41 Build 3
Affected Version To: v.6.41 Build 3
Patch Exists: NO
Related CWE:
CPE: a:internet_download_manager:internet_download_manager:6.41_build_3
Platforms Tested: Windows 10 Professional x64
2022
Internet Download Manager v6.41 Build 3 – Remote Code Execution (RCE)
Some help files are missing in non-English versions of Internet Download Manager. Help files with the extension '.chm' prepared in the language used are downloaded from the internet and run, and displayed to users. This download is done over HTTP, which is an insecure protocol. An attacker on the local network can spoof traffic with a MITM attack and replaces '.chm' help files with malicious '.chm' files. IDM runs '.chm' files automatically after downloading. This allows the attacker to execute code remotely. It also uses HTTP for checking and downloading updates by IDM. The attacker can send fake updates as if the victim has a new update to the system.
Mitigation:
Ensure that all help files are downloaded over a secure protocol such as HTTPS. Ensure that all updates are downloaded over a secure protocol such as HTTPS. Ensure that all users have the least privileges necessary to perform their tasks.