Vulnerability record · CVE-2023-37907 · published 25 July 2023
CVE-2023-37907: Cryptomator improper privilege management vulnerability
Cryptomator · Cryptomator
Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege escalation (LPE) for low privileged users, if already installed. The problem occurs as the repair function of the MSI spawns two administrative CMDs. A simple LPE is possible via a breakout. Version 1.9.2 fixes this issue.
Description
Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege escalation (LPE) for low privileged users, if already installed. The problem occurs as the repair function of the MSI spawns two administrative CMDs. A simple LPE is possible via a breakout. Version 1.9.2 fixes this issue.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/cryptomator/cryptomator/commit/b48ebd524b1626bf12ac98e35a7670b868fa208c | Patch |
| https://github.com/cryptomator/cryptomator/releases/tag/1.9.2 | Release Notes |
| https://github.com/cryptomator/cryptomator/security/advisories/GHSA-9c9p-c3mg-hpjq | ExploitIssue TrackingVendor Advisory |
| https://github.com/cryptomator/cryptomator/commit/b48ebd524b1626bf12ac98e35a7670b868fa208c | Patch |
| https://github.com/cryptomator/cryptomator/releases/tag/1.9.2 | Release Notes |
| https://github.com/cryptomator/cryptomator/security/advisories/GHSA-9c9p-c3mg-hpjq | ExploitIssue TrackingVendor Advisory |
Track CVE-2023-37907 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-37907), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.