CVE-2024-38272
low-risk
Published 2024-06-26
There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above
Do I need to act?
-
0.01% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.3/10
Medium
ADJACENT_NETWORK
/ LOW complexity
Affected Products (1)
Nearby
Affected Vendors
References (4)
Issue Tracking
https://github.com/google/nearby/pull/2402
Issue Tracking
https://github.com/google/nearby/pull/2589
Issue Tracking
https://github.com/google/nearby/pull/2402
Issue Tracking
https://github.com/google/nearby/pull/2589
20
/ 100
low-risk
Severity
15/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal