Vulnerabilities > Druva > Insync Client > High

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2021-36665 Deserialization of Untrusted Data vulnerability in Druva Insync Client
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
local
low complexity
druva CWE-502
7.2
2022-07-12 CVE-2021-36666 Untrusted Search Path vulnerability in Druva Insync Client
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
local
low complexity
druva CWE-426
7.8
2020-05-21 CVE-2020-5752 Path Traversal vulnerability in Druva Insync Client 6.6.3
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
local
low complexity
druva CWE-22
7.8
2020-02-25 CVE-2019-3999 OS Command Injection vulnerability in Druva Insync Client 6.5.0
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
local
low complexity
druva CWE-78
7.2