CVE-2024-39613

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*

History

20 Sep 2024, 13:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:mattermost:mattermost_desktop:*:*:*:*:*:*:*:*
First Time Mattermost
Mattermost mattermost Desktop
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory

16 Sep 2024, 15:30

Type Values Removed Values Added
Summary
  • (es) Las versiones de la aplicación de escritorio Mattermost &lt;=5.8.0 no pueden especificar una ruta absoluta al buscar el archivo cmd.exe, lo que permite que un atacante local que pueda colocar un archivo cmd.exe en la carpeta Descargas de la máquina de un usuario provoque la ejecución remota de código en esa máquina.

16 Sep 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-16 07:15

Updated : 2024-09-20 13:59


NVD link : CVE-2024-39613

Mitre link : CVE-2024-39613

CVE.ORG link : CVE-2024-39613


JSON object : View

Products Affected

mattermost

  • mattermost_desktop
CWE
CWE-427

Uncontrolled Search Path Element