Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37617

Опубликовано: 18 авг. 2021
Источник: nvd
CVSS3: 7.3
CVSS2: 4.4
EPSS Низкий

Описание

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the Uninstall.exe file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious Uninstall.exe, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the C:\ system folder and verify that there is no malicious C:\Uninstall.exe file on the system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:*
Версия от 3.0.3 (включая) до 3.3.0 (исключая)

EPSS

Процентиль: 53%
0.00299
Низкий

7.3 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-426
CWE-427

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 4 лет назад

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the `Uninstall.exe` file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious `Uninstall.exe`, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the `C:\` system folder and verify that there is no malicious `C:\Uninstall.exe` file on the system.

CVSS3: 7.3
debian
больше 4 лет назад

The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...

EPSS

Процентиль: 53%
0.00299
Низкий

7.3 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-426
CWE-427