XINJE XDPPro.exe Insecure Permissions Vulnerability in XNetSocketClient Component Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in the XNetSocketClient component of XINJE XDPPro.exe, specifically in versions 3.2.2 to 3.7.17c. The issue arises from insecure permissions that allow attackers to execute arbitrary code by modifying the application's configuration file.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the user running the application.

Reproduction

To reproduce this vulnerability, first install XINJE XDPPro.exe version 3.2.2 to 3.7.17c. Once installed, navigate to the application's configuration file. Due to the insecure permissions, an unauthorized user can modify this file. After making changes, the application can be launched, executing the injected code or commands.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.