CVE-2024-50307
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
- EPSS probability
- 0.26%
- CWE
- CWE-676
- Published
- 2024-10-28
- Last modified
- 2026-03-13
Affected products
- kubell Co., Ltd. Chatwork Desktop Application (Windows)
Weakness type
Related vulnerabilities
- CVE-2025-14601 — vsDesk Task Scheduler OS Command Injection
- CVE-2026-14501 — Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
- CVE-2026-54499 — Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- CVE-2025-67604 — A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through...
- CVE-2025-65117 — AVEVA Process Optimization Use of Potentially Dangerous Function
- CVE-2024-38434 — Unitronics Vision PLC - CWE-676: Use of Potentially Dangerous Function
- CVE-2022-39063 — When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for...
- CVE-2021-27474 — Rockwell Automation FactoryTalk AssetCentre Use of Potentially Dangerous Function