CVE-2024-10668 is an authentication bypass vulnerability in Google Quick Share for Windows, allowing an attacker to upload arbitrary, unknown file types to a victim's Downloads folder. The flaw stems from Quick Share's incomplete deletion logic when processing duplicate file transfer frames, leaving the second malicious file on the system. With a CVSS score of 7.5 (High), this vulnerability requires no user interaction or authentication (AV:N/AC:L/PR:N/UI:N), potentially leading to high availability impact (A:H) by allowing persistent unauthorized file delivery. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, indicating awareness. Organizations are advised to upgrade to Quick Share Windows v1.0.2002.2 or apply commit 5d8b9156e0c339d82d3dab0849187e8819ad92c0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.2002.2CPE matchmatch criteria | cpe:2.3:a:google:quick_share:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:A/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Green
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.