cve/2024/CVE-2024-37885.md
2024-06-22 09:37:59 +00:00

900 B

CVE-2024-37885

Description

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.

POC

Reference

No PoCs from references.

Github