WD Discovery Desktop App for Windows Vulnerability Enables Arbitrary Code Execution
A security vulnerability has been identified in the WD Discovery desktop application by Western Digital, which could allow attackers to execute arbitrary code on Windows systems.
A security vulnerability has been identified in the WD Discovery desktop application by Western Digital, which could allow attackers to execute arbitrary code on Windows systems.
The vulnerability, designated as CVE-2025-30248, impacts WD Discovery version 5.2.730 and all earlier versions. It involves a DLL hijacking vulnerability within the WD Discovery installer, exploiting the way Windows loads dynamic-link library (DLL) files.
Local attackers can place a malicious DLL file in the installer's search path, leading the legitimate application to load and execute it, providing the attacker with full code execution capabilities on the target system.
Western Digital has also identified further EXE and DLL hijacking vulnerabilities within the Tiny Installer component used by WD Discovery. These additional attack vectors increase the security risk for users operating vulnerable versions, especially in environments with shared workstations or weaker physical security controls.
The vulnerability, designated as CVE-2025-30248, impacts WD Discovery version 5.2.730 and all earlier versions.
The vulnerability has been assigned a CVSS 4.0 score of 8.9, indicating a high severity level. Successful exploitation allows attackers to execute arbitrary code with the same privileges as the WD Discovery installer, potentially compromising the entire system.
Western Digital released WD Discovery version 5.3 on December 19, 2025, addressing all identified vulnerabilities. Users will receive automatic update notifications through the application, prompting them to install the security patch. Alternatively, users can manually download version 5.3 from the official WD Discovery Downloads page.
It is advised that Windows users running any version of WD Discovery prior to 5.3 update their installations immediately to mitigate potential exploitation risks.
Western Digital acknowledges the contributions of Kazuma Matsumoto from GMO Cybersecurity by IERAE, Inc., and David Silva for responsibly disclosing these vulnerabilities through coordinated disclosure processes.
Based on reporting by Cyber Security News.
