Junglewise Threat Intelligence

CVE-2016-10646: resourcehacker insecure HTTP download of executable

CVE-2016-10646 · Severity: info · CVSS 0 · Published 2018-08-15

Vendors: npm.

Executive brief

resourcehacker is a Node.js library used to manipulate Windows resource files. The package downloads an executable over unencrypted HTTP during installation, allowing an attacker on the network path to intercept and replace it with malicious code, leading to remote code execution on the user's system.

Technical details

resourcehacker contains an insecure download vulnerability (CWE-311: Missing Encryption of Sensitive Data) where an executable is fetched over unencrypted HTTP during package installation. An attacker with network access (man-in-the-middle position) can intercept the HTTP response and replace the legitimate executable with malicious code, achieving code execution on the affected system. This requires the attacker to have a privileged network position such as control of the local network, ISP access, or DNS spoofing capability. No patch has been released; the only mitigation is to avoid using the package or to restrict installation to trusted private networks only.

Affected products

  • npm resourcehacker all versions

Timeline

  • 2018-08-15: disclosed
  • 2020-06-16: other: GitHub reviewed and confirmed