Western Digital desktop app exposes Windows and macOS users to attack

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

Western Digital’s proprietary file explorer EdgeRover, has received a patch that addresses a critical security vulnerability.

The fixed flaw, tracked as CVE-2022-22998, is a directory traversal bug, which essentially means - people were allowed to access restricted files. Discovered by cybersecurity researcher Xavier Danest, it’s been given a severity score of 9.1. 

The good news is that the endpoint already needs to be compromised, if this vulnerability is to be abused. In a published advisory, the company said very little about the flaw itself, other than if successfully exploited, could lead to the disclosure of sensitive information or denial-of-service.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

A patch is available

All EdgeRover users are advised to update their endpoints to version 1.5.1.-594, or newer. The fix corrects both file and directory permissions. 

Western Digital did not say if the vulnerability was abused in the wild through viruses or malware. It’s even difficult to say how many people use EdgeRover, but given the overall popularity of Western Digital, as a brand, it’s safe to assume that some people could be vulnerable. 

EdgeRover is a personal content management application, for Western Digital and SanDisk hardware, promising simplicity, usability, as well as advanced features such as powerful search, categorization, the detection of duplicate files, and similar. 

The application is available for both Windows and Mac OS. 

Just like any other hardware manufacturer out there, Western Digital is no stranger to vulnerabilities. Late last year, it warned owners of the My Cloud NAS devices to update to the latest firmware immediately, as the older versions were being terminated due to an increasing number of attacks. 

“My Cloud OS 5 is a major and fundamental security release that provides an architectural revamp of our older My Cloud firmware and adds new defenses to thwart common classes of attacks,” WD explained back then.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
A person&#039;s fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Top file synchronization tool Rsync security flaws mean up to 660,000 servers possibly affected
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch
Promotional image for Malcolm in the Middle featuring the original cast playing golf
Malcolm in the Middle's Disney+ revival gets underway as the series finds its cast – here's which characters are returning
Group of people meeting
Inflexible work policies are pushing tech workers to quit
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
Youtube
YouTube Premium could be getting a new time-saving perk, showing you recommended videos directly in your playback queue
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype