CVE-2024-37885: Code injection in Nextcloud Desktop Client for macOS
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLDINSERTLIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37885?
CVE-2024-37885 is considered a critical vulnerability due to the potential for code injection.
How do I fix CVE-2024-37885?
To fix CVE-2024-37885, update the Nextcloud Desktop Client to version 3.12.0 or newer.
Which versions of Nextcloud Desktop Client are affected by CVE-2024-37885?
CVE-2024-37885 affects Nextcloud Desktop Client versions prior to 3.12.0.
What platforms are impacted by CVE-2024-37885?
CVE-2024-37885 specifically impacts the Nextcloud Desktop Client on macOS.
What could happen if I don't address CVE-2024-37885?
If CVE-2024-37885 is not addressed, an attacker could execute arbitrary code on your macOS system.