Archive of posts from 2023

Finding applications vulnerable to CVE-2023-4863 (WebP)

Finding applications vulnerable to CVE-2023-4863 (WebP)

Mike Garuccio
Read Time 8 min Read

Last week Google announced a buffer overlflow vulnerability in the WebP media format that impacts both browsers and electron applications that handle media. Most vendors have released patches to fix their software, but, how can you make sure that every application in your environment that needs to be patched actually has been? Using Elastic and OSquery to find WebP...