Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://sysdream.com/news/lab/2018-09-21-cve-2018-13140-antidote-remote-code-execution-against-the-update-component/ | third party advisory exploit |
http://seclists.org/fulldisclosure/2018/Sep/38 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/149468/Antidote-9.5.1-Code-Execution.html | exploit vdb entry third party advisory |