PT-2026-64959 · Unknown · Nitroshare-Desktop
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NitroShare Desktop versions prior to 0.3.5
Description
The LAN file transfer server contains a path traversal issue that allows unauthenticated attackers on the same network to write arbitrary files. This occurs because the server fails to validate paths when processing the
name field within the JSON item header. By sending a crafted filename containing directory traversal sequences, an attacker can write files outside the intended transfer root directory to any location where the current user has write permissions, such as the Windows Startup folder, which can lead to persistent code execution upon the next user login.Recommendations
Update NitroShare Desktop to version 0.3.5 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nitroshare-Desktop