SB2021081902 - Multiple vulnerabilities in Nextcloud Desktop Client



SB2021081902 - Multiple vulnerabilities in Nextcloud Desktop Client

Published: August 19, 2021

Security Bulletin ID SB2021081902
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Untrusted search path (CVE-ID: CVE-2021-37617)

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to uncontrolled search path. A remote attacker can create a malicious "Uninstall.exe" and execute it with administrative privileges on the target system.


2) Improper Certificate Validation (CVE-ID: CVE-2021-32728)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the client fails to check if a private key belongs to previously downloaded public certificate. A remote attacker can encrypt the data on the target system.


Remediation

Install update from vendor's website.