Multiple Vulnerabilities in GoSign Desktop lead to Remote Code Execution

Multiple vulnerabilities in GoSign Desktop allow for Remote Code Execution and Privilege Escalation due to disabled TLS certificate validation and an unsigned update mechanism. A fix was released in version 2.4.1, but the TLS validation issue remains unresolved.

Edward Kiledjian @ekiledjian