EUVD-2026-33913
ID: EUVD-2026-33913
Severity: medium
CVSS v4: Not provided
CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
CWE: None listed
Source: ENISA
Description
D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.
Timestamps
- Normalized:
- Last updated:
References
No references provided.