News: 1647876613

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Western Digital tells EdgeRover users to patch app again

(2022/03/21)


Users of Western Digital's [1]EdgeRover app for Windows and Mac are advised to download an updated version to avoid a security flaw that might allow an attacker unauthorized access to directories and files.

The flaw, which was given the CVE identification number [2]CVE-2022-22988 , carries a Common Vulnerability Scoring System (CVSS) severity rating of 9.1, making it a critical weakness. It has now been addressed, however, with a modification to the way EdgeRover handles file and directory permissions.

According to Western Digital, the flaw meant that EdgeRover was subject to a directory traversal vulnerability, which may have allowed an attacker to carry out a local privilege escalation and bypass file system sandboxing. If successfully exploited, this could lead to the disclosure of sensitive information or even a potential denial-of-service attack, the firm said.

[3]

Western Digital posted a [4]notification to its support site informing users of both the Windows and Mac versions of the EdgeRover Desktop App that they need to ensure they are running release version 1.5.1-594 at a minimum in order to have the fix for this issue.

[5]This browser-in-browser attack is perfect for phishing

[6]Cyclops Blink malware sets up shop in ASUS routers

[7]Exotic Lily is a business-like access broker for ransomware gangs

[8]CISOs face 'perfect storm' of ransomware and state-supported cybercrime

The EdgeRover app is designed to provide users with a single view of their content, which may be spread across multiple storage devices and cloud storage services. EdgeRover creates a searchable and browsable catalog of all content, and also provides tools to manage supported Western Digital and SanDisk storage devices.

In particular, EdgeRover is able to change vital settings on supported Western Digital and SanDisk devices, including the ability to set passwords, delete content, and rename devices, which would allow an attacker plenty of scope to cause mischief.

[9]

This is not the first security fix for EdgeRover to come this year. In January, the firm advised users to [10]download an updated release to address multiple vulnerabilities, but in that case these were due to an [11]open-source tool , the FFmpeg multimedia framework, which EdgeRover makes use of.

With that vulnerability, an exploit might have caused a denial of service or allowed an attacker to execute code through the avenue of presenting malformed files or streams to be processed. That vulnerability also carried a CVSS severity rating of 9.1. ®

Get our [12]Tech Resources



[1] https://www.westerndigital.com/en-gb/support/software/edgerover

[2] https://nvd.nist.gov/vuln/detail/cve-2022-22988

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjivQ0bD@cJMCWPDjHgLAQAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.westerndigital.com/support/product-security/wdc-22004-edgerover-desktop-app-version-1-5-1-594

[5] https://www.theregister.com/2022/03/18/browser_in_browser_phishing/

[6] https://www.theregister.com/2022/03/18/cyclops_asus_routers/

[7] https://www.theregister.com/2022/03/18/exotic_lily_iab_google/

[8] https://www.theregister.com/2022/03/18/ciso_security_storm/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjivQ0bD@cJMCWPDjHgLAQAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.westerndigital.com/support/product-security/wdc-22003-edgerover-desktop-app-version-1-5-0-576

[11] https://www.theregister.com/2021/10/20/vizio_gpl_lawsuit/

[12] https://whitepapers.theregister.com/



thosrtanner

the mind boggles as to why this app needs to play mpeg files

badflorist

It probably wants to create a thumbnail from some part of the video(s).

"... EdgeRover is able to change vital settings ..."

Should of never went that far, should of stayed just a browser.

Three rules for sounding like an expert:
(1) Oversimplify your explanations to the point of uselessness.
(2) Always point out second-order effects, but never point out
when they can be ignored.
(3) Come up with three rules of your own.