ZeroHour

CVE-2018-7295

PoC
CVSS 3.0
8.1 high
EPSS
<1%p36
Published
()
Modified
Description

ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During Transmission in a Communication Channel, allowing a man-in-the-middle attacker to steal user credentials because a session retrieves global.js via http before proceeding to use https. This is fixed in Patch 4.3.

Vendors
square-enix
Products
final fantasy xiv
Weakness
CWE-924
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.