Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-37617

Опубликовано: 18 авг. 2021
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 4.4
CVSS3: 7.3

Описание

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the Uninstall.exe file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious Uninstall.exe, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the C:\ system folder and verify that there is no malicious C:\Uninstall.exe file on the system.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-infra-legacy/trusty

DNE

focal

not-affected

hirsute

not-affected

impish

not-affected

jammy

not-affected

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 53%
0.00299
Низкий

4.4 Medium

CVSS2

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
больше 4 лет назад

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the `Uninstall.exe` file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious `Uninstall.exe`, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the `C:\` system folder and verify that there is no malicious `C:\Uninstall.exe` file on the system.

CVSS3: 7.3
debian
больше 4 лет назад

The Nextcloud Desktop Client is a tool to synchronize files from Nextc ...

EPSS

Процентиль: 53%
0.00299
Низкий

4.4 Medium

CVSS2

7.3 High

CVSS3

Уязвимость CVE-2021-37617