PT-2023-26176 · Unknown · Cryptomator

·

CVE-2023-37907

·

Published

2023-07-25

·

Updated

2023-08-03

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cryptomator versions prior to 1.9.2
Description The issue affects data encryption software for cloud storage, allowing local privilege escalation for low-privileged users if the software is already installed. This occurs because the repair function of the MSI installer spawns administrative CMDs, making a simple breakout possible.
Recommendations For versions prior to 1.9.2, update to version 1.9.2 to resolve the issue. As a temporary workaround, consider restricting the use of the repair function in the MSI installer until the update is applied.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37907
GHSA-9C9P-C3MG-HPJQ

Affected Products

Cryptomator