There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above
Advisories
Source ID Title
EUVD EUVD EUVD-2024-37237 There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 24 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google nearby
CPEs cpe:2.3:a:google:nearby:*:*:*:*:*:*:*:*
Vendors & Products Google
Google nearby
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2024-08-02T04:04:25.233Z

Reserved: 2024-06-12T09:23:33.130Z

Link: CVE-2024-38272

cve-icon Vulnrichment

Updated: 2024-06-26T17:11:43.726Z

cve-icon NVD

Status : Modified

Published: 2024-06-26T16:15:11.733

Modified: 2024-11-21T09:25:12.743

Link: CVE-2024-38272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.