高危
TrueConf Client更新完整性校验绕过漏洞
2026-03-30 18:05:42 公开 ,2026-04-05 03:41:19 更新
- APT漏洞
- CISA KEV
- 关键漏洞
- 公开PoC
- CWEs:
- CWE-494 (Download of Code Without Integrity Check)
- CAPEC:
- CAPEC-184 (Software Integrity Attack) 、 CAPEC-185 (Malicious Software Download) 、 CAPEC-186 (Malicious Software Update) 、 CAPEC-187 (Malicious Automated Software Update via Redirection) 、 CAPEC-533 (Malicious Manual Software Update) 、 CAPEC-538 (Open-Source Library Manipulation) 、 CAPEC-657 (Malicious Automated Software Update via Spoofing) 、 CAPEC-662 (Adversary in the Browser (AiTB)) 、 CAPEC-691 (Spoof Open-Source Software Metadata) 、 CAPEC-692 (Spoof Version Control System Commit Metadata) 、 CAPEC-693 (StarJacking) 、 CAPEC-695 (Repo Jacking)
- SSVC:
- 可利用状态:已被积极利用攻击自动化:否技术影响评估:全部 2026-03-31 08:00:00