#VU92219 Security features bypass in Dropbox Desktop - CVE-2024-5924
Published: June 18, 2024
Dropbox Desktop
Dropbox
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not apply the Mark-of-the-Web to the local files when syncing files from a shared folder belonging to an untrusted account. A remote attacker can bypass the Mark-of-the-Web protection mechanism and execute arbitrary code on the system.