RSS   Vulnerabilities for 'Desktop'   RSS

2021-08-18
 
CVE-2021-37617

CWE-426
 

 
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the Client searches the `Uninstall.exe` file in a folder that can be written by regular users. This could lead to a case where a malicious user creates a malicious `Uninstall.exe`, which would be executed with administrative privileges on the Nextcloud Desktop Client installation. This issue is fixed in Nextcloud Desktop Client version 3.3.0. As a workaround, do not allow untrusted users to create content in the `C:\` system folder and verify that there is no malicious `C:\Uninstall.exe` file on the system.

 
2021-04-14
 
CVE-2021-22879

CWE-74
 

 
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.

 

 >>> Vendor: Nextcloud 18 Products
MAIL
Desktop
TALK
Server
NEWS
Calendar
Nextcloud
Nextcloud server
Lookup-server
Circles
DECK
Group folders
Nextcloud mail
Contacts
Preferred providers
Social
Richdocuments
Officeonline


Copyright 2024, cxsecurity.com

 

Back to Top