Vulnerability Description
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Evernote | Evernote | < 7.13 |
Related Weaknesses (CWE)
References
- https://evernote.com/security/updates#MACOSNOTE-28956Vendor Advisory
- https://www.youtube.com/watch?v=OG2tKlZX5bgExploitThird Party Advisory
- https://evernote.com/security/updates#MACOSNOTE-28956Vendor Advisory
- https://www.youtube.com/watch?v=OG2tKlZX5bgExploitThird Party Advisory
FAQ
What is CVE-2019-17051?
CVE-2019-17051 is a vulnerability with a CVSS score of 7.8 (HIGH). Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop oper...
How severe is CVE-2019-17051?
CVE-2019-17051 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17051?
Check the references section above for vendor advisories and patch information. Affected products include: Evernote Evernote.