logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-39520

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-39520

Description:
Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local privilege escalation for low privileged users, via the `repair` function. The problem occurs as the repair function of the MSI is spawning an SYSTEM Powershell without the `-NoProfile` parameter. Therefore the profile of the user starting the repair will be loaded. Version 1.9.3 contains a fix for this issue. Adding a `-NoProfile` to the powershell is a possible workaround.
Last updated date:
08/11/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/11/2023
Reference url to background

https://github.com/cryptomator/cryptomator/security/advisories/GHSA-62gx-54j7-mjh3

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy