CVE-2022-41882 is a high-severity vulnerability in the Nextcloud Desktop Client (version 3.6.0) that allows for arbitrary code execution. If a user receives a malicious file share and either syncs it locally or has virtual filesystem enabled, clicking a specially crafted "nc://open/" link can execute the file via the default editor, particularly on Windows with file types like "vbs." The vulnerability has a CVSS score of 7.8 (High), indicating a low attack complexity and no required privileges, but user interaction is necessary. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.6.0CPE matchmatch criteria | cpe:2.3:a:nextcloud:desktop:3.6.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.