Executive brief
NiceHash QuickMiner, a cryptocurrency mining software, contains a vulnerability in its automatic update mechanism. The software reportedly downloads updates over an unencrypted connection without verifying the authenticity of the files. An attacker who can intercept the network traffic could replace the legitimate update with malicious software, allowing them to take full control of the user's computer. Note that the vendor disputes this claim, stating that the software uses secure connections exclusively.
Technical details
NiceHash QuickMiner 6.12.0 is reported to download software updates via an unencrypted HTTP connection (CWE-494). The update process allegedly fails to perform digital signature verification or cryptographic hash checks on the downloaded binaries. A network-positioned attacker capable of intercepting or redirecting traffic (Man-in-the-Middle) could hijack the update request and serve a malicious executable. Because the software automatically executes the downloaded update, this results in full remote code execution (RCE) with the privileges of the miner. The vendor has disputed this report, claiming the referenced HTTP update URL is a fabrication and that the product uses HTTPS.
Affected products
- NiceHash QuickMiner 6.12.0
Timeline
- 2025-09-30: disclosed
- 2025-09-30: advisory
- 2026-05-11: other: Vulnerability disputed by vendor