Memory Corruption Vulnerability in NextCloud Desktop Client by NextCloud
CVE-2020-8230

5.5MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
17 August 2020

What is CVE-2020-8230?

The NextCloud Desktop Client version 2.6.4 is impacted by a memory corruption vulnerability due to the lack of Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) protections on Windows systems. This weakness allows attackers to corrupt memory, potentially leading to unauthorized actions or data breaches. It is crucial for users of this application to apply the appropriate updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Desktop Client 2.6.5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.