Description
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of shared folders. When syncing files from a shared folder belonging to an untrusted account, the Dropbox desktop application does not apply the Mark-of-the-Web to the local files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-23991.
Published: 2024-06-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-47053 Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of shared folders. When syncing files from a shared folder belonging to an untrusted account, the Dropbox desktop application does not apply the Mark-of-the-Web to the local files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-23991.
History

Sat, 23 Nov 2024 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Dropbox dropbox Desktop
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:dropbox:dropbox_desktop:198.4.7615:*:*:*:*:*:*:*
Vendors & Products Dropbox dropbox Desktop
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Dropbox Dropbox Dropbox Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-08-01T21:25:03.164Z

Reserved: 2024-06-12T19:05:13.638Z

Link: CVE-2024-5924

cve-icon Vulnrichment

Updated: 2024-07-15T17:00:28.634Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-13T20:15:16.000

Modified: 2024-11-23T00:42:38.983

Link: CVE-2024-5924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses