Hex-Dragon Plain Craft Launcher
cpe:2.3:a:plain_craft_launcher_2_project:plain_craft_launcher_2:*:*:*:*:*:*:*
- <= 2.9.2
A vulnerability in Plain Craft Launcher (PCL) versions through 2.9.2 allows for unnoticed access to specified webpages via Internet Explorer. This occurs when a user selects a malicious homepage that utilizes WebBrowser controls, which WPF applications load using Internet Explorer in the background. The vulnerability has been addressed in PCL version 2.9.3 by disabling unsafe controls, adding more security checks, and providing warnings before using third-party homepages.
Exploitation of this vulnerability could lead to unauthorized access of webpages specified by the user, without their knowledge.
Users are advised to update Plain Craft Launcher to version 2.9.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.