Technology newsroom
Severe Alert! Belgian eID Software Vulnerability Affects 2 Million Users, Risking Hacker Control π±
A Critical security vulnerability has been found in Belgium's eID software, impacting over 2 million users, including major banks and numerous government agencies. Users are at risk of hackers taking control of their devices via dangerous link clicks.
π Key Takeaways:
- A critical-level severe vulnerability has been discovered in Connective software, used with electronic identity cards (eID) in Belgium.
- Over 2 million users are at risk, including customers of 8 major banks and users of over 60 government agencies.
- Hackers can exploit this vulnerability to execute remote code (RCE) on victims' machines simply by luring them to click a link on a fake website.
Security researchers from SECFORCE have disclosed the discovery of two critical security vulnerabilities in the Middleware software used for electronic identity cards (eID) in Belgium. This has a massive widespread impact, as the software is used by over 2 million people nationwide.
The problematic software is "Connective," which acts as an intermediary, allowing users to verify their identity and digitally sign documents using their eID via web browsers. The discovered vulnerabilities, CVE-2024-28825 and CVE-2024-3747, enable attackers to create malicious websites to trick users into clicking, stealthily executing harmful code on the victim's computer instantly, known as Remote Code Execution (RCE).
π¨ Impact and Damage
The frightening aspect of this vulnerability is the ease of attack. Malicious actors only need to create a convincing fake webpage and send a link via phishing emails or social media channels. When a user with an older version of Connective software clicks the link, hackers can remotely control the victim's computer, which could lead to malware installation, theft of personal or financial data, or complete system takeover.
Particularly concerning is that this software is widely used in numerous large organizations, including 8 out of 10 of Belgium's largest banks and over 60 government agencies. This means a vast amount of sensitive data and financial transactions are at risk. Connective has now released a patch to fix these vulnerabilities and urges all users and organizations to update their software to the latest version as soon as possible.
π¬ How often does your organization check and update software used for digital identity verification? Share your best practices here!