logo

Multiple Vulnerabilities in GoSign Desktop lead to Remote Code Execution

ID: 534b7e24-af9d-5c2a-ad68-905b2a4ad9cc

STIX ID: report--534b7e24-af9d-5c2a-ad68-905b2a4ad9cc

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2025-11-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

This advisory reports critical vulnerabilities in GoSign Desktop 2.4.0: TLS certificate validation is disabled when a proxy is configured and the update mechanism relies on an unsigned manifest, enabling MitM attacks that can deliver malicious updates and achieve remote code execution and credential exfiltration; a PoC and technical details were published, a CVSS 3.1 score of 8.2 was assigned, and a partial fix (2.4.1) was released which reportedly does not restore TLS validation when a proxy is used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.