PT-2023-26992 · Unknown · Cryptomator

Pfiatde

·

Publicado

2023-08-07

·

Atualizado

2025-04-10

·

CVE-2023-39520

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cryptomator version 1.9.2
Description Cryptomator encrypts data being stored on cloud infrastructure. The issue allows local privilege escalation for low privileged users via the repair function. This occurs because the repair function of the MSI installer spawns a SYSTEM Powershell without the -NoProfile parameter, loading the profile of the user starting the repair.
Recommendations For Cryptomator version 1.9.2, update to version 1.9.3 to resolve the issue. As a temporary workaround, consider adding a -NoProfile parameter to the Powershell command to prevent the user's profile from being loaded during the repair process.

Exploit

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39520
GHSA-62GX-54J7-MJH3

Produtos afetados

Cryptomator