Medium severity5.5NVD Advisory· Published Aug 7, 2023· Updated Jun 17, 2026
CVE-2023-39520
CVE-2023-39520
Description
Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local privilege escalation for low privileged users, via the repair function. The problem occurs as the repair function of the MSI is spawning an SYSTEM Powershell without the -NoProfile parameter. Therefore the profile of the user starting the repair will be loaded. Version 1.9.3 contains a fix for this issue. Adding a -NoProfile to the powershell is a possible workaround.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:*range: <1.9.3
- (no CPE)range: <1.9.3
- (no CPE)range: <= 1.9.2
Patches
Vulnerability mechanics
References
4- github.com/cryptomator/cryptomator/commit/727c32ad50c3901a6144a11cf984a3b7ebcf8b2bnvdPatch
- github.com/cryptomator/cryptomator/security/advisories/GHSA-62gx-54j7-mjh3nvdExploitMitigationVendor Advisory
- github.com/cryptomator/cryptomator/releases/download/1.9.2/Cryptomator-1.9.2-x64.msinvdProduct
- github.com/cryptomator/cryptomator/releases/tag/1.9.3nvdRelease Notes
News mentions
0No linked articles in our index yet.