Discover how CVE-2020-14049 affects Viber for Windows up to version 13.2.0.39. Learn about the risks, impact, and mitigation steps to secure your system.
Viber for Windows up to version 13.2.0.39 is vulnerable to a security issue that could allow a malicious website to launch Viber with arbitrary parameters, potentially leading to NTLM authentication request interception.
Understanding CVE-2020-14049
This CVE identifies a vulnerability in Viber for Windows that could be exploited by a malicious actor to intercept NTLM authentication requests.
What is CVE-2020-14049?
Viber for Windows up to version 13.2.0.39 does not properly handle its custom URI handler, enabling a malicious website to manipulate Viber with arbitrary parameters.
The Impact of CVE-2020-14049
The vulnerability could result in a victim unknowingly sending an NTLM authentication request, allowing an attacker to potentially capture the hash for offline password cracking.
Technical Details of CVE-2020-14049
Viber for Windows is susceptible to exploitation due to improper handling of custom URI parameters.
Vulnerability Description
The issue arises from Viber's failure to adequately quote its custom URI handler, leaving it open to manipulation by external sources.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
It is crucial to take immediate steps to address and prevent exploitation of this vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates