Impact
NitroShare Desktop through version 0.3.4 suffers from a path traversal flaw in its LAN file transfer server that lets an unauthenticated attacker on the same network send a crafted JSON header containing directory traversal sequences. This allows the attacker to write files outside the intended transfer root, including to the Windows Startup folder, enabling persistent code execution when the user next logs on. The vulnerability directly provides attacker‑controlled file write capability in the context of the current user, which can be used to drop and run arbitrary binaries or scripts. The formal severity is reflected in a CVSS score of 8.7, indicating high potential for compromise.
Affected Systems
All installations of NitroShare Desktop up to and including version 0.3.4 are affected. The issue is specific to the LAN file transfer component and, based on the description, it is inferred that it can be exploited on any operating system where NitroShare runs, although the example of the Windows Startup folder suggests that Windows users are most directly impacted. No other versions are listed as affected.
Risk and Exploitability
The flaw can be triggered over a local network by any host that can reach the NitroShare file transfer service; no special privileges or prior authentication are required. Because the attacker can write arbitrary files with the current user’s permissions, the threat includes both immediate file manipulation and long‑term persistence through startup execution. The CVSS score of 8.7 reflects the high impact and ease of exploitation, while an EPSS score of 0.00737 (under 1%) indicates a low but non‑zero exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the lack of access controls and path validation gives the attacker an unimpeded path to modify system state with potential for widespread damage.
OpenCVE Enrichment