PT-2023-26176 · Unknown · Cryptomator

Pfiatde

·

Publicado

2023-07-25

·

Atualizado

2023-08-03

·

CVE-2023-37907

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cryptomator versions prior to 1.9.2
Description The issue affects data encryption software for cloud storage, allowing local privilege escalation for low-privileged users if the software is already installed. This occurs because the repair function of the MSI installer spawns administrative CMDs, making a simple breakout possible.
Recommendations For versions prior to 1.9.2, update to version 1.9.2 to resolve the issue. As a temporary workaround, consider restricting the use of the repair function in the MSI installer until the update is applied.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37907
GHSA-9C9P-C3MG-HPJQ

Produtos afetados

Cryptomator