Keybase是一套基于PGP技术的、支持端到端加密的社交网络平台。 Keybase Client for Windows 5.7.0之前版本存在安全漏洞,攻击者可利用该漏洞使用精心编制的文件名将文件上载到共享文件夹,导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Video Communications Inc | Keybase Client for Windows | unspecified ~ 5.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-34417 | 7.9 HIGH | Authenticated remote command execution with root privileges via web console in MMR |
| CVE-2021-34420 | 4.7 MEDIUM | Zoom Windows installation executable signature bypass |
| CVE-2021-34418 | 4.0 MEDIUM | Pre-auth Null pointer crash in on-premise web console |
| CVE-2021-34419 | 3.7 LOW | HTML injection in Zoom Linux client |
| CVE-2021-34421 | 3.7 LOW | Retained exploded messages in Keybase Clients for Android and iOS |
No comments yet