CVE-2023-37907 HIGH

CVE-2023-37907: Cryptomator's MSI installer allows local privilege escalation

Vendor Cryptomator
Product cryptomator
Weakness CWE-269
Published July 25, 2023
Last update October 3, 2024

CVSS base score

7.0/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege escalation (LPE) for low privileged users, if already installed. The problem occurs as the repair function of the MSI spawns two administrative CMDs. A simple LPE is possible via a breakout. Version 1.9.2 fixes this issue.

Key dates

02Disclosure timeline

July 25, 2023 CVE published
October 3, 2024 Record updated