CVE-2024-22169
Description
CVE-2024-22169 allows code execution in WD Discovery app via Electron environment variable misconfiguration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2024-22169 allows code execution in WD Discovery app via Electron environment variable misconfiguration.
Vulnerability
Description CVE-2024-22169 is a misconfiguration in the Node.js environment settings of WD Discovery versions prior to 5.0.589. The vulnerability allows an attacker to utilize the ELECTRON_RUN_AS_NODE environment variable to execute arbitrary code within the context of the WD Discovery application [1]. This is due to insecure Electron fuses and Node.js settings that were not properly disabled [1].
Attack
Vector and Exploitation Any malicious application operating with standard user permissions can exploit this vulnerability [1]. The attack requires the victim to have the WD Discovery application installed on their device [1]. The attacker must be able to set the environment variable before WD Discovery starts, which could be achieved through a separate compromised application or script running on the same machine.
Impact
Successful exploitation enables code execution within the WD Discovery application's context [1]. This could allow an attacker to perform actions with the same privileges as the WD Discovery app, potentially accessing files, system resources, or other sensitive data that the application has access to.
Mitigation
Western Digital addressed this vulnerability in WD Discovery version 5.0.589 by disabling certain features and fuses in Electron [1]. Users are automatically prompted to update, or they can download the latest version from the WD Discovery Downloads page [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <5.0.589
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.