Junglewise Threat Intelligence

CVE-2022-36077: Electron credential exfiltration via file:// redirect on Windows

CVE-2022-36077 · Severity: low · CVSS 3.1 · Published 2022-11-10

Executive brief

Electron is a framework used to build desktop applications with web technologies. On Windows, a flaw in redirect handling allows attackers to trick the application into connecting to attacker-controlled SMB servers, causing Windows to transmit hashed SMB credentials (NTLM authentication hashes) that can potentially be captured and cracked. This could lead to unauthorized access to Windows user accounts or network resources.

Technical details

The vulnerability is an information disclosure flaw (CWE-200, CWE-522) in Electron's redirect handling logic. When an Electron application follows a redirect from another scheme to a file:// URL, the framework delays validation of the target scheme. If the redirect target is crafted as an SMB URL (file://attacker.com/), Windows automatically attempts NTLM authentication with the attacker's server, potentially sending hashed credentials. The attack requires no user interaction and is network-reachable but has high attack complexity due to redirect chain requirements. Fixes are available in Electron 18.3.7, 19.0.11, 20.0.1, and all 21.x versions; a workaround exists via event handlers to block file:// redirects.

Affected products

  • Electron Electron < 18.3.7, >= 19.0.0-beta.1 < 19.0.11, >= 20.0.0-beta.1 < 20.0.1

Timeline

  • 2022-11-07: disclosed
  • 2022-11-10: patched: Fixes released in versions 18.3.7, 19.0.11, 20.0.1, and 21.0.0-beta.1

References