First published: Tue Dec 14 2021(Updated: )
A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository could leverage this vulnerability to potentially execute arbitrary Windows commands on a user\'s local system.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Keybase Keybase | <5.6.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34426 is a vulnerability discovered in the Keybase Client for Windows before version 5.6.0 that allows a malicious actor with write access to a user's Git repository to execute arbitrary code.
CVE-2021-34426 affects Keybase Client for Windows versions prior to 5.6.0.
CVE-2021-34426 has a severity rating of 7.8 (high).
The vulnerability in Keybase Client can be exploited by a malicious actor with write access to a user's Git repository executing the "keybase git lfs-config" command on the command-line.
No, Microsoft Windows is not vulnerable to CVE-2021-34426.